OWASP Periodic Table of Vulnerabilities - Clickjacking

Revision as of 14:35, 14 May 2013 by James Landis (Talk | contribs)

Jump to: navigation, search

Return to Periodic Table Working View



Root Cause Summary

User agents allow target sites to be framed and mouse clicks to be intercepted/redirected to the target site. Users may believe they are clicking on a visible UI element, but their click is actually redirected to a different element on the target site.

Browser / Standards Solution

CSP should define a white list of domains which are allowed to load the site in a frame. Default should be SAMEORIGIN. Policy should allow custom rules for specific URLs within the site, to allow a subset of pages to have custom framing rules.

Perimeter Solution


Generic Framework Solution

The framework should provide a configurable white list for domains according to the requirements for the CSP standard. Until the CSP standard is finalized, the framework should use the white list rules in order to set the appropriate X-Frame-Options headers in each response.

The framework should detect the user-agent version; if the UA does not support CSP or XFO, the framework should inject the appropriate framebusting code automatically or redirect to a browser upgrade message if the desired policy cannot be implemented without CSP/XFO.

Custom Framework Solution


Custom Code Solution


Discussion / Controversy

Generic UI redressing may be too difficult to solve quickly, but would be a better long-term solution than framing policy rules alone.


research and recommendation