2014Unpublished venueRequires access

Clickjuggler: Checking for incomplete defenses against clickjacking

Yusuke Takamatsu, Kenji Kono

Open publisher page 7 citations

Abstract

Clickjacking is a new attack which exploits a vulnerability in web applications. It tricks victims into clicking on something different from what they perceive they are clicking on. The victims may reveal confidential information or start unintended online transactions. Clickjacking can be prevented if appropriate countermeasures such as frame busting are implemented in web applications. However, the correct implementation is not easy. A trivial mistake in the implementation leads to evasion of the countermeasures. For the correct implementation, web developers must have intimate knowledge on evasion techniques of the countermeasures. In this paper, we propose Clickjuggler, an automated tool for checking for defenses against clickjacking during the development. Clickjuggler generates clickjacking attacks, performs those attacks on web applications, and checks whether the attacks are successful or not. By automating the process of checking for the clickjacking vulnerabilities, web developers are released from the burden of checking the correctness of their implementation. Unskillful developers can benefit from Clickjuggler since no special knowledge on clickjacking is needed to use Clickjuggler. Our experimental results demonstrate that Clickjuggler can check for the clickjacking vulnerabilities in 4 real-world web applications.

About this research paper

What this paper is about

Clickjacking is a new attack which exploits a vulnerability in web applications. It tricks victims into clicking on something different from what they perceive they are clicking on. The victims may reveal confidential information or start unintended online transactions. Clickjacking can be prevented if appropriate countermeasures such as frame busting are implemented in web applications. However, the correct implementation is not easy. A trivial mistake in the implementation leads to evasion of the countermeasures. For the correct implementation, web developers must have intimate knowledge on evasion techniques of the countermeasures. In this paper, we propose Clickjuggler, an automated tool for checking for defenses against clickjacking during the development. Clickjuggler generates clickjacking attacks, performs those attacks on web applications, and checks whether the attacks are successful or not. By automating the process of checking for the clickjacking vulnerabilities, web developers are released from the burden of checking the correctness of their implementation. Unskillful developers can benefit from Clickjuggler since no special knowledge on clickjacking is needed to use Clickjuggler. Our experimental results demonstrate that Clickjuggler can check for the clickjacking vulnerabilities in 4 real-world web applications.

Why it matters

OpenAlex reports 7 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Clickjacking is a new attack which exploits a vulnerability in web applications. It tricks victims into clicking on something different from what they perceive they are clicking on. The victims may reveal confidential information or start unintended online transactions. Clickjacking can be prevented if appropriate countermeasures such as frame busting are implemented in web applications. However, the correct implementation is not easy. A trivial mistake in the implementation leads to evasion of the countermeasures. For the correct implementation, web developers must have intimate knowledge on evasion techniques of the countermeasures. In this paper, we propose Clickjuggler, an automated tool for checking for defenses against clickjacking during the development. Clickjuggler generates clickjacking attacks, performs those attacks on web applications, and checks whether the attacks are successful or not. By automating the process of checking for the clickjacking vulnerabilities, web developers are released from the burden of checking the correctness of their implementation. Unskillful developers can benefit from Clickjuggler since no special knowledge on clickjacking is needed to use Clickjuggler. Our experimental results demonstrate that Clickjuggler can check for the clickjacking vulnerabilities in 4 real-world web applications.

Key concepts: Computer science, Correctness, Computer security, Evasion (ethics), Exploit, Mistake, Web application, Vulnerability (computing)

Related papers

Back to paper searchBrowse research topicsOriginal source
Clickjuggler: Checking for incomplete defenses against clickjacking — Research Paper | ScholarLens