Clickjacking


Clickjacking, aka user interface redressing, is a client-side attack that takes advantage of some of the page rendering features that are available in newer web browsers.

  • attacker must legitimately control or have taken control of some portion of a website
  • Attacker constructs or modifies the site by placing an invisible layer over something the client would normally click
  • this executes a command