What is Clickjacking: Clickjacking attack allows to perform an action on victim website, Mostly Facebook and Twitter accounts are targetable. when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the the top level page. Thus, the attacker is "hijacking" clicks meant for their page and routing them to other another page, most likely owned by another application, domain, or both. It may be similar to CSRF Cross Site Request Forgeries Attack. Clickjacking is a term first introduced by Jeremiah Grossman and Robert Hansen in 2008 to describe a technique whereby an attacker tricks a user into performing certain actions on a website by hiding clickable elements inside an invisible iframe. Using a similar technique, keystrokes can also be hijacked. With a carefully crafted combination of stylesheets, iframes, and text boxes, a user can be led to believe they are typing in the password to their email or bank account, but are instead typing into an invisible frame controlled by the attacker. At present this attack mostly use on social network websites like Facebook and twitter, Because this attack is used by convinced victim for click on the link and SocialNetwork website might be very useful for attack on victim. One famous example of clickjacking is Facebook. | Code: <style> iframe { /* iframe from facebook.com */ width:300px; height:100px; position:absolute; top:0; left:0; filter:alpha(opacity=50); /* in real life opacity=0 */ opacity:0.5; } </style> <div>Click on the link to get more followers:</div> <iframe src="/files/tutorial/window/clicktarget.html"></iframe> <a href="http://www.google.com" target="_blank" style="position:relative;left:20px;z-index:-1">CLICK ME!</a> <div>You'll be get 10000 followers..!!</div> Output: Click on the link to get more followersClick Me You'll be get 10000 followers..!!Download ClickJacking Tool For Defence: Clickjacking Protection For more information: OWASP |
yllex
Thursday, October 8, 2015
Popular Posts
-
Download Flipkart Ewallet Hack Tool without survey Flipkart wallet hacker, money adder without survey Download Now - http://linkshrink.net/7...
-
it's Not A Trick It's Funny App called " Whatsaid - Whatsapp Prank " install WhatSaid on your Android device and Start cre...
-
This trick may be secret for you. If unfortunately if lost your messages and you’re searching to get back these messages again in your inbox...
-
How to Hack Facebook Account Password There are various methods to hack facbook account password like Keyloggers, Phishing websites etc.....
-
How to Hack a Website with Basic HTML Coding If you have basic HTML and JavaScript knowledge, you may be able to access password protected w...
-
How To Run Android Apps In Pc As we are going to using an Android Emulator, you must download an Android Emulator first. We recommend you...
-
How to Stop Someone’s Internet Access If you want to stop someone’s internet access. Then here is the easy notepad trick. Step By Step Proc...
-
Hello Friends, Today I am going to say you about URL Traffic Manipulation, which we perform using ARP ( Address Resolution Protocol ) Poison...
-
How To View Facebook Private Profile Photo In Large Size ? Sometime you want to see clear image of someone on facebook who might not be you...
-
I Am Going To Post How To Unblock Yourself From Someone's Whatsapp Account When Someone Blocked You, But Now You Can Unblock Yourself An...
0 comments:
Post a Comment