15–25 min Updated

Clickjacking

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

As an application author, you need to be sure your users aren't having their clicks stolen by attackers.

Prevalence
Occasional
Exploitability
Easy
Impact
Harmful

What is clickjacking?

Clickjacking is a user interface redress attack in which an attacker loads your site in an invisible frame layered over a page they control. The victim believes they are clicking a harmless button, but the click lands on your site, triggering an action such as a purchase, a like or a settings change without their consent.

What you'll learn

  • How an invisible frame and a transparent overlay steal a click
  • Why any page can frame your site unless you forbid it
  • How Content Security Policy, X-Frame-Options and frame-killing stop clickjacking

Where this lesson counts

OWASP Top 10

  • Clickjacking lab

    You run the most popular kitten video site on the internet. Watch an attacker frame your page on a lookalike domain, lay a transparent link over the video and steal the click. Then click the video yourself and see where you end up.

  • How to prevent Clickjacking

    The prevention guide covers three approaches:

    • Content Security Policy
    • X-Frame-Options
    • Frame-Killing
  • Clickjacking quiz

    Three questions. Passing marks the lesson complete.

Sources

  • Cross-Site Request Forgery

    If an attacker can forge HTTP requests to your site, they may be able to trick your users into triggering unintended actions.

  • Cross-Site Scripting

    If your site allows users to add content, you need to be sure that attackers cannot inject malicious JavaScript.

  • Open Redirects

    Most web-applications make use of redirects. If your site forwards to URLs supplied in a query string, you could be enabling phishing attacks.

  • Malvertising

    Embedded adverts are a common target for hackers.