What is Clickjacking: Clickjacking attack allows to perform an action on victim website, Mostly Facebook and Twitter accounts are targetable. when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the the top level page. Thus, the attacker is "hijacking" clicks meant for their page and routing them to other another page, most likely owned by another application, domain, or both. It may be similar to CSRF Cross Site Request Forgeries Attack. Clickjacking is a term first introduced by Jeremiah Grossman and Robert Hansen in 2008 to describe a technique whereby an attacker tricks a user into performing certain actions on a website by hiding clickable elements inside an invisible iframe. Using a similar technique, keystrokes can also be hijacked. With a carefully crafted combination of stylesheets, iframes, and text boxes, a user can be led to believe they are typing in the password to their email or bank account, but are instead typing into an invisible frame controlled by the attacker. At present this attack mostly use on social network websites like Facebook and twitter, Because this attack is used by convinced victim for click on the link and SocialNetwork website might be very useful for attack on victim. One famous example of clickjacking is Facebook. | Code: <style> iframe { /* iframe from facebook.com */ width:300px; height:100px; position:absolute; top:0; left:0; filter:alpha(opacity=50); /* in real life opacity=0 */ opacity:0.5; } </style> <div>Click on the link to get more followers:</div> <iframe src="/files/tutorial/window/clicktarget.html"></iframe> <a href="http://www.google.com" target="_blank" style="position:relative;left:20px;z-index:-1">CLICK ME!</a> <div>You'll be get 10000 followers..!!</div> Output: Click on the link to get more followersClick Me You'll be get 10000 followers..!!Download ClickJacking Tool For Defence: Clickjacking Protection For more information: OWASP |
yllex
Thursday, October 8, 2015
Popular Posts
-
Its an official offer and we have tested this on Delhi its working fine , its confirmed that its working fine on Delhi circle . How to Get...
-
Hello Friends, Here is The New Working Method For Hack Someone Whatsapp Account, It's Working 100% Now,Tested by me Today Spoo...
-
Internshala Is Now Promoting Their New Refer And Earn Campaign Where They Are Giving Out Lots Of Free Recharges With As Much As Rs30 Per Fri...
-
Samsung Secret Codes Software version: *#9999# IMEI number: *#06#Serial number: *#0001#Battery status- Memory capacity : *#9998*246# Debug s...
-
Paytm has come up with a new cashback offer for Mobile recharges and bill payments. It is giving flat Rs 50 cashback on mobile recharges or ...
-
Now you can make unlimited free spoof calling, Without losing any money/balance * Download one caller id changer - http://sh.st/vlOfT * Put ...
-
Hello Friends, As the name suggests,Today i am going to tell you all a trick by use of which you will be able to download paid software...
-
Temple run Oz hacked without mod (Unlimited Coins And Gems! ). TRY now! Hello friends I have made a post after many days since October So h...
-
How to Protect Hacking Valuable tips to prevent hacking, How to Protect Hacking of Facebook, How to Protect Ha...
0 comments:
Post a Comment