Clickjacking
Clickjacking is a framed page that still performs a state change. Read the framing policy first. The note is the missing policy plus the action a click would complete, on an account you own.
Skill
No skill is linked for this class yet. Start with the playbook on this page.
Practice the class in the browser: PortSwigger Web Security Academy. The lab is theirs. This page is the stop condition and the disclosures.
Checklists
None linked for this class yet.
Disclosures
No public card yet.
Playbooks
- Clickjacking and framing policy - A framed page is a finding only when a click still completes a state change. Read the framing headers, name the action, and stop. Do not publish a frame.
Payloads
- Clickjacking / UI redress - Frame an authenticated sensitive page. Proof is a framed screenshot of a state-changing UI you own, plus missing X-Frame-Options / CSP frame-ancestors.
Bypasses
- Frame-ancestors / XFO gaps - The sensitive page is the one that matters. Marketing sites are almost always framable and almost never in scope as a finding.
Questions
The page has no X-Frame-Options. Is that the report?
A missing header is the primitive. The report needs a state change that a framed click would complete, such as a payment, a role change, or a confirmation the user cannot see.
Do I publish a frame to prove it?
No. Describe the page, the action, and the headers you observed. A hosted frame is not required for the note, and this site does not provide one.
This page is the linked pack hunt_brief("clickjacking") returns on the MCP connector. Authorized testing only.