
Clickjacking
by yaklang6fbf0bc8d5c7No license2.4K starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 3 weeks ago
Clickjacking playbook. Use when testing whether target pages can be framed, whether X-Frame-Options or CSP frame-ancestors are properly configured, and whether UI redress attacks can trigger sensitive actions.
Only the file list is public. File contents are available once the skill is installed in a workspace.
| Path | Size | Type |
|---|---|---|
| SKILL.md | 4.9 KB | text/markdown |
Source and attribution
Source:yaklang/hack-skillsinskills/clickjackingat commit6fbf0bc
License: No license
Content belongs to its original authors. SourceWeft indexes it from a public repository.
More from yaklang/hack-skills

Web Cache Deception
yaklang
Playbook for testing web cache deception and cache poisoning flaws in CDNs, proxies and app caching.

Type Juggling
yaklang
Explains PHP type juggling and weak comparison bypasses for loose equality, magic hashes, and HMAC checks.

Open Redirect
yaklang
An offensive security playbook for finding and exploiting open redirect vulnerabilities and chaining them into phishing, OAuth token theft and SSRF.

Nosql Injection
yaklang
A NoSQL injection testing playbook covering MongoDB operator injection, blind extraction, aggregation pipelines, CouchDB and Redis.

Idor Broken Object Authorization
yaklang
Playbook for testing IDOR and broken object-level authorization, covering attack vectors, A-B testing and privilege escalation.

Csv Formula Injection
yaklang
Covers CSV and spreadsheet formula injection, including DDE payloads, obfuscation, Google Sheets import functions, testing and defense.
More in Security

Kyc Rules
anthropics
Applies a firm's KYC/AML rules grid to a parsed onboarding record, scoring risk and routing outcomes.

Compliance Tracking
anthropics
Tracks compliance requirements, audit readiness, and evidence for frameworks such as SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS.

Dpop Adoption
Guides implementation of OAuth 2.0 DPoP (RFC 9449) sender-constrained refresh tokens for Google's OAuth platform.

Secops Triage
Guides SOC analysts through triaging Google SecOps security alerts, from investigation to closure or escalation.

Secops Investigate
Guides SOC analysts through deep security incident and entity investigations in Google SecOps using UDM queries and timelines.

Secops Hunt
Guides proactive threat hunting in Google SecOps using UDM queries, IoC lookback, prevalence and outlier analysis.