But if they are able to hack into the server, I supposed there is nothing to do then...
[1] http://www.w3.org/TR/CSP/#frame-src
If my assumption is correct, then CSP won't help unless we separate the source server and the proxy server from each other.
But if they are able to hack into the server, I supposed there is nothing to do then...