What is Clickjacking: Clickjacking attack allows to perform an action on victim website, Mostly Facebook and Twitter accounts are targetable. when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the the top level page. Thus, the attacker is "hijacking" clicks meant for their page and routing them to other another page, most likely owned by another application, domain, or both. It may be similar to CSRF Cross Site Request Forgeries Attack. Clickjacking is a term first introduced by Jeremiah Grossman and Robert Hansen in 2008 to describe a technique whereby an attacker tricks a user into performing certain actions on a website by hiding clickable elements inside an invisible iframe. Using a similar technique, keystrokes can also be hijacked. With a carefully crafted combination of stylesheets, iframes, and text boxes, a user can be led to believe they are typing in the password to their email or bank account, but are instead typing into an invisible frame controlled by the attacker. At present this attack mostly use on social network websites like Facebook and twitter, Because this attack is used by convinced victim for click on the link and SocialNetwork website might be very useful for attack on victim. One famous example of clickjacking is Facebook. | Code: <style> iframe { /* iframe from facebook.com */ width:300px; height:100px; position:absolute; top:0; left:0; filter:alpha(opacity=50); /* in real life opacity=0 */ opacity:0.5; } </style> <div>Click on the link to get more followers:</div> <iframe src="/files/tutorial/window/clicktarget.html"></iframe> <a href="http://www.google.com" target="_blank" style="position:relative;left:20px;z-index:-1">CLICK ME!</a> <div>You'll be get 10000 followers..!!</div> Output: Click on the link to get more followersClick Me You'll be get 10000 followers..!!Download ClickJacking Tool For Defence: Clickjacking Protection For more information: OWASP |
yllex
Thursday, October 8, 2015
Popular Posts
-
Today millions of users are using the latest version of Windows that is Windows 8 and 8.1 which is currently providing lots of features for ...
-
Al.ly is The New Shorten Url Money making site, it gives 1.5$/1000 views http://al.ly Minimum withdrawal of only $1.00, Get paid with PayPal...
-
Here's the List of Steps to Bypass Passcode: You need to follow these simple steps to bypass passcode on any iOS device running ...
-
Reliance Mobile has extended its True Unlimited 3G supply until August 15 as associate degree legal holiday supply. Earlier, we have a tende...
-
Use 3Gb per month on Finch VPN For Free (Don't pay for it!)| Simple Trick by Yogesh Tech The World | Hurry! Hello everyone. I have Pos...
-
you can transfer your all bookmyshow wallet money to a single account...Looted BookMyShow ? If yes then i have a awesome trick for you !!! N...
-
Steps for this tricks :- You need Facebook or Twitter pack. Goto one.airtel.in and activate facebook or twitter trial pack. Download Hammer...
-
How To Get Rs 300 cashback on adding Rs 300 in mobikwik Wallet :- 1) Go to Mobikwik.com 2) Initiate adding Rs 300 in the wallet. 3) Use your...
-
Advanced wapka forums functions like: > Set Hit Quote to copy > How to Use textarea in forums > cool input type=text format > co...
-
Getting an approved adsense account these days is a very difficult matter. But I have discovered a good trick to be automatically accepted...
0 comments:
Post a Comment