clickjacking

Clickjacking playbook. Use when testing whether target pages can be framed, whether X-Frame-Options or CSP frame-ancestors are properly configured, and whether UI redress attacks can trigger sensitive actions.

By yaklang · 2,979 installs

npx skills add yaklang/hack-skills --skill clickjacking

Source repository · Upstream listing

SKILL: Clickjacking — Expert Attack Playbook AI LOAD INSTRUCTION : Clickjacking (UI redress) techniques. Covers iframe transparency tricks, X Frame Options bypass, CSP frame ancestors, multi step clickjacking, drag and drop attacks, and chaining with other vulnerabilities. Often a "low severity" finding that becomes critical when targeting admin actions. 1. CORE CONCEPT Clickjacking loads a target page in a transparent iframe overlaid on an attacker's page. The victim sees the attacker's UI but clicks on the invisible target page, performing unintended actions. 2. DETECTION — IS THE PAGE FRAMEABLE? Check X Frame Options Header Check CSP frame ancestors CSP frame ancestors supersedes X Frame Options in modern browsers. Quick PoC Test If the page loads in the iframe → frameable → potentially vulnerable. JavaScript Frame Detection (from target page source) If this code is present but not using CSP frame ancestors , it can often be bypassed. 3. PROOF OF CONCEPT TEMPLATES Basic Single Click Multi Step Clickjacking For actions requiring multiple clicks (e.g., "Are you sure?" confirmation): Reposition iframe for each step to align the transparent button with the decoy. Drag and Drop Clickjacking Extract data from one iframe to another using HTML5 drag and drop events — the victim drags across invisible iframes, transferring tokens or data. 4. BYPASS TECHNIQUES Frame Busting Script Bypass Some pages use JavaScript frame busting: Bypass with sandbox attribute : X Frame Options ALLOW FROM Bypass ALLOW FROM is not supported in Chrome/Safari. If the server relies solely on ALLOW FROM , modern browsers ignore it → page is frameable. Double Framing If X Frame Options: SAMEORIGIN is set, but a same origin page exists that can be framed (without XFO), use that page as an intermediary to frame the target. 5. HIGH IMPACT TARGETS 6. TESTING CHECKLIST