<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: frame_ancestors_missing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/frame-ancestors-missing/m-p/586263#M117012</link>
    <description>&lt;P&gt;Thank you so much for the solution. You made my day. I wasn't expecting that I am gonna find your post.&amp;nbsp;I was actually searching for this &lt;A href="https://academized.com/custom-thesis" target="_blank"&gt;https://academized.com/custom-thesis&lt;/A&gt; website online because my younger brother needs custom thesis writing help and when I was searching for it online, I found link to your post as well.&lt;/P&gt;</description>
    <pubDate>Mon, 20 May 2024 08:20:15 GMT</pubDate>
    <dc:creator>AveryHawkins</dc:creator>
    <dc:date>2024-05-20T08:20:15Z</dc:date>
    <item>
      <title>frame_ancestors_missing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/frame-ancestors-missing/m-p/582943#M116541</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;BR /&gt;I run a regular scan on our equipment from a public source and I am seeing the following vuln being flagged against the URL that is used for our Palo devices and I was hoping someone would have an answer as there's not much information out there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Analysis refers to:&amp;nbsp;&lt;/P&gt;
&lt;H2 class="Heading__HeadingH2--1e961ka hdPeoI ssc-ds-typography"&gt;Site Does Not Use Best Practices Against Embedding of Malicious Content&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The host header ; frame_ancestors_missing&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hoping someone can advise&amp;nbsp;&lt;BR /&gt;Many thanks&lt;/P&gt;
&lt;P&gt;D&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 14:48:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/frame-ancestors-missing/m-p/582943#M116541</guid>
      <dc:creator>DinoAdami</dc:creator>
      <dc:date>2024-04-08T14:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: frame_ancestors_missing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/frame-ancestors-missing/m-p/582967#M116547</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/118866"&gt;@DinoAdami&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;frame-ancestors are served up in the CSP header and essentially just limit the ability to embed a page to whatever you have specified. Whatever you're using for scanning is properly reporting that this isn't present for GlobalProtect; I'm unaware of any ability to customize this behavior. You can reach out to your SE to get a FR put together to add this functionality however.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 20:36:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/frame-ancestors-missing/m-p/582967#M116547</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-04-08T20:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: frame_ancestors_missing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/frame-ancestors-missing/m-p/583014#M116558</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for this, I received a response from our support partner early this morning and their response is along the same lines. Do you know of any official Palo documentation that advises as such, I'm unable to find anything that outlines this behaviour - I can go back to the online scanner; SecurityScorecard.io to have this false positive removed.&lt;/P&gt;
&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 08:22:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/frame-ancestors-missing/m-p/583014#M116558</guid>
      <dc:creator>DinoAdami</dc:creator>
      <dc:date>2024-04-09T08:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: frame_ancestors_missing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/frame-ancestors-missing/m-p/583044#M116565</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/118866"&gt;@DinoAdami&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I'm not aware of any official documentation specifically stating that frame-ancestors isn't supported; that's kind of asking for documentation to support the lack of a specific functionality, it isn't extremely common that a vendor will take the time to publish that information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also want to be clear here that this isn't really a false-positive detection. Your scanner is properly documenting the lack of a specific functionality that would make things more secure if it was utilized, the product that it's scanning simply doesn't support said functionality.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 13:36:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/frame-ancestors-missing/m-p/583044#M116565</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-04-09T13:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: frame_ancestors_missing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/frame-ancestors-missing/m-p/586263#M117012</link>
      <description>&lt;P&gt;Thank you so much for the solution. You made my day. I wasn't expecting that I am gonna find your post.&amp;nbsp;I was actually searching for this &lt;A href="https://academized.com/custom-thesis" target="_blank"&gt;https://academized.com/custom-thesis&lt;/A&gt; website online because my younger brother needs custom thesis writing help and when I was searching for it online, I found link to your post as well.&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 08:20:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/frame-ancestors-missing/m-p/586263#M117012</guid>
      <dc:creator>AveryHawkins</dc:creator>
      <dc:date>2024-05-20T08:20:15Z</dc:date>
    </item>
  </channel>
</rss>

