SKILL: Clickjacking — Expert Attack Playbook
AI LOAD INSTRUCTION: Clickjacking (UI redress) techniques. Covers iframe transparency tricks, X-Frame-Options bypass, CSP frame-ancestors, multi-step clickjacking, drag-and-drop attacks, and chaining with other vulnerabilities. Often a "low severity" finding that becomes critical when targeting admin actions.
1. CORE CONCEPT
Clickjacking loads a target page in a transparent iframe overlaid on an attacker's page. The victim sees the attacker's UI but clicks on the invisible target page, performing unintended actions.
2. DETECTION — IS THE PAGE FRAMEABLE?
Check X-Frame-Options Header
Check CSP frame-ancestors
CSP frame-ancestors supersedes X-Frame-Options in modern browsers.
Quick PoC Test
If the page loads in the iframe → frameable → potentially vulnerable.
JavaScript Frame Detection (from target page source)
If this code is present but not using CSP frame-ancestors, it can often be bypassed.
3. PROOF OF CONCEPT TEMPLATES
Basic Single-Click
Multi-Step Clickjacking
For actions requiring multiple clicks (e.g., "Are you sure?" confirmation):
Reposition iframe for each step to align the transparent button with the decoy.
Drag-and-Drop Clickjacking
Extract data from one iframe to another using HTML5 drag-and-drop events — the victim drags across invisible iframes, transferring tokens or data.
4. BYPASS TECHNIQUES
Frame-Busting Script Bypass
Some pages use JavaScript frame-busting:
Bypass with sandbox attribute:
X-Frame-Options ALLOW-FROM Bypass
ALLOW-FROM is not supported in Chrome/Safari. If the server relies solely on ALLOW-FROM, modern browsers ignore it → page is frameable.
Double-Framing
If X-Frame-Options: SAMEORIGIN is set, but a same-origin page exists that can be framed (without XFO), use that page as an intermediary to frame the target.


