On the fragility and limitations of current browser-provided clickjacking protection schemes

  • Authors:
  • Sebastian Lekies;Mario Heiderich;Dennis Appelt;Thorsten Holz;Martin Johns

  • Affiliations:
  • SAP Research;University Bochum;SAP Research;University Bochum;SAP Research

  • Venue:
  • WOOT'12 Proceedings of the 6th USENIX conference on Offensive Technologies
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

An important and timely attack technique on the Web is Clickjacking (also called UI redressing), in which an attacker tricks the unsuspicious victim into clicking on a specific element without his explicit knowledge about where he is actually clicking. In order to protect their websites from being exploitable, many web masters deployed different countermeasures to this kind of attack. In this paper, we explore the limitations and shortcomings of current anti-clickjacking approaches and present several bypasses of state-of-the-art tools, including an attack we call Nested Clickjacking that enables us to perform Clickjacking against the social network Google+. Furthermore, we present the results of a large scale empirical study on the usage of current anti-clickjacking mechanisms on about 2 million web pages. The results of our analysis show that about 15% of the analyzed web sites protect themselves against Clickjacking.