Definition · Security Headers

What is Clickjacking?

Clickjacking, sometimes called a UI redress attack, exploits the fact that a browser will happily render another site inside a frame while the user’s session cookies for that site still apply. The attacker builds a page with attractive bait — a video play button, a competition entry, a download link — and positions the victim site in a transparent or precisely offset frame above it. The user aims at the bait and actually clicks a button on the framed application, authenticated as themselves.

Variants extend the same idea. Likejacking targets social media actions. Cursorjacking misrepresents the pointer position. Drag-and-drop attacks use framed content to move data between origins rather than to trigger a click.

What an attacker can achieve

Anything a single authenticated interaction can do: approving a payment or an OAuth consent screen, changing a setting, enabling a permission, deleting content, or granting access. It does not let the attacker read the framed page — the same-origin policy still applies — so clickjacking is about causing state-changing actions blind, not about exfiltrating data. Application endpoints where one click has significant consequences are the ones worth protecting hardest.

Defences

  • Content-Security-Policy: frame-ancestors — the current, precise control. 'none' forbids framing entirely; a list of origins permits only those.
  • X-Frame-Options — the older header, with DENY and SAMEORIGIN. Where both are present, modern browsers honour frame-ancestors, so setting both is a compatibility measure rather than a conflict.
  • SameSite cookies — Lax or Strict means cookies are not sent with many cross-site framed requests, which blunts the attack even where framing is possible.
  • Confirmation steps for consequential actions — re-authentication or a typed confirmation defeats a single stolen click.

Legacy JavaScript “frame busting” scripts are not a substitute; they have been bypassed in numerous ways and can be neutralised by the sandbox attribute on the framing iframe.

Checking your own estate

Framing protection is a per-response header, so it is easy for it to be present on the main application and absent on an older subdomain, a marketing site, or an admin panel behind a different server. Auditing across every host, not just the flagship domain, is the part organisations most often get wrong.

See CSP, X-Frame-Options, cross-site scripting, security headers and OWASP Top Ten.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.