I was asked to check how to prevent Clickjacking on our website.
I did some research and this is what I understand, please correct me if I'm wrong: The attacker will use iframe to layer their website over your website, then make their iframe transparent. When user click on a button on our website, they are actually clicking on hacker website. To prevent this, disable iframe on our website.
I went to this website to check, but I got this error:
Couldn’t find the X-Frame-Options header in the response headers.
What it means? I'm not sure.
I also searched online and found that you need to add this code in .htaccess
<IfModule mod_headers.c>
Header always append X-Frame-Options SAMEORIGIN
</IfModule>
But how do I know if it works?