{"repo":"Automattic/Adbusters","free":true,"listed":false,"github":"https://github.com/Automattic/Adbusters","clone":"git clone https://github.com/Automattic/Adbusters.git","description":"A WordPress plugin that loads a set of iframe busters for popular ad networks","language":"HTML","stars":29,"topics":["wordpress","wordpress-plugin","wpvip-plugin"],"license":"GPL-3.0","category":"security-tools","readme_excerpt":"Adbusters for WordPress A WordPress plugin that loads a set of iframe busters for popular ad networks. Download the plugin from WordPress.org. Have you found a bug, or have a feature request? Github pull requests are warmly received. :) Guidelines for iFrame Busters The following are common XSS vulnerabilities found in iFrame busters. 1. Unescaped URL parameter values 2. Parameters that accept any domain Unescaped URL parameter values Special characters should be removed or converted into their equivalent HTML/hex entity. The characters in the following table can be used to write malicious code on the page. example.com/iframebuster.html?parameter=\" alert('XSS') Character = HTML Entity & = &amp; &lt; = &gt; \" = &quot; ' = &#x27; / = &#x2F; Parameters that accept any domain When passing a domain as a parameter to write a script tag onto the page, it should be restricted to an approved domain(s). example.com/iframebuster.html?server=evildomain.com Examples of Safe iFrame Busters DARTIframe.html ifr b.html Pictela iframeproxy.html XSS Attack Prevention Guidelines Further guidelines can be found at ha.ckers.org/xss.html, which covers the above rules as well as many others.","default_branch":null,"files":null,"tree":[],"storefront":"/r/Automattic","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Automattic/Adbusters/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}