clickjacking

Busting Frame Busting a Study of Clickjacking Vulnerabilities on Popular Sites

By , , ,   @W2SP 2010
0 reaction(s) | 2405 downloads
We study frame busting defense for the Alexa Top-500 sites and show that all can be broken. Some attacks are browser-specific, other exploit code mistakes. We conclude with practical recommendations how to implement a secure frame busting defense.
You liked it, share it !
Downloads
paper
slides
You might also like reading

Clickjacking 2010

Framing Attacks on Smartphones Dumb Routers and Social Sites Tap-jacking Geo-localization and Framing Leak Attacks

Blog 2011

What Phishing Sites Look Like Study

Mobile 2012

SessionJuggler Secure Web Login from an Untrusted Terminal Using Session Hijacking

Embedded devices 2009

XCS cross channel scripting and its impact on web applications

Web security 2010

An Analysis of Private Browsing Modes in Modern Browsers

Comments
About me
Researcher at Google, specializing in Internet security and privacy.
Latest blog posts
Latest social News
1 day ago
New "tool": HULK, Web Server DoS Tool - http://t.co/dWlcrq2v #security #pentesting #web
New survey: 19% of users use their browser private mode - http://t.co/2BTgm6SA #security #privacy #infosec #smo
19% of users use their browser private mode - http://t.co/ed2NqpaZ #security #privacy #infosec
Blizzard fixing GAME Australia's bankruptcy mess, giving Diablo 3 to those who preordered - http://t.co/JjpVm5X5 #d3 #diablo #diablo3
SessionJuggler Secure Web Login from an Untrusted Terminal Using Session Hijacking - http://t.co/IRQsBcVY #security #infosec #www2012...