Clickjacking
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
As an application author, you need to be sure your users aren't having their clicks stolen by attackers.
- Prevalence
- Occasional
- Exploitability
- Easy
- Impact
- Harmful
What is clickjacking?
Clickjacking is a user interface redress attack in which an attacker loads your site in an invisible frame layered over a page they control. The victim believes they are clicking a harmless button, but the click lands on your site, triggering an action such as a purchase, a like or a settings change without their consent.
What you'll learn
- How an invisible frame and a transparent overlay steal a click
- Why any page can frame your site unless you forbid it
- How Content Security Policy, X-Frame-Options and frame-killing stop clickjacking
Where this lesson counts
OWASP Top 10
Missing threat modelling and security requirements leave flaws no amount of careful coding can fix.
OWASP files UI redress under Insecure Design: the fix is a design decision about who may frame your pages.
Learn more about A06This lesson includes
-
Clickjacking lab
You run the most popular kitten video site on the internet. Watch an attacker frame your page on a lookalike domain, lay a transparent link over the video and steal the click. Then click the video yourself and see where you end up.
-
How to prevent Clickjacking
The prevention guide covers three approaches:
- Content Security Policy
- X-Frame-Options
- Frame-Killing
-
Clickjacking quiz
Three questions. Passing marks the lesson complete.
Sources
- Clickjacking MDN
- Content Security Policy MDN
- Clickjacking (UI redress) PortSwigger
- Clickjacking Defense Cheat Sheet OWASP
Related lessons
Browse all 45 lessons
Cross-Site Request Forgery
If an attacker can forge HTTP requests to your site, they may be able to trick your users into triggering unintended actions.
Cross-Site Scripting
If your site allows users to add content, you need to be sure that attackers cannot inject malicious JavaScript.
Open Redirects
Most web-applications make use of redirects. If your site forwards to URLs supplied in a query string, you could be enabling phishing attacks.
Malvertising
Embedded adverts are a common target for hackers.