vulns.co
/
GKData.io MCP

Clickjacking

Clickjacking is a framed page that still performs a state change. Read the framing policy first. The note is the missing policy plus the action a click would complete, on an account you own.

Skill

No skill is linked for this class yet. Start with the playbook on this page.

Practice the class in the browser: PortSwigger Web Security Academy. The lab is theirs. This page is the stop condition and the disclosures.

Checklists

None linked for this class yet.

Disclosures

No public card yet.

Playbooks

  • Clickjacking and framing policy - A framed page is a finding only when a click still completes a state change. Read the framing headers, name the action, and stop. Do not publish a frame.

Payloads

  • Clickjacking / UI redress - Frame an authenticated sensitive page. Proof is a framed screenshot of a state-changing UI you own, plus missing X-Frame-Options / CSP frame-ancestors.

Bypasses

  • Frame-ancestors / XFO gaps - The sensitive page is the one that matters. Marketing sites are almost always framable and almost never in scope as a finding.

Questions

The page has no X-Frame-Options. Is that the report?

A missing header is the primitive. The report needs a state change that a framed click would complete, such as a payment, a role change, or a confirmation the user cannot see.

Do I publish a frame to prove it?

No. Describe the page, the action, and the headers you observed. A hosted frame is not required for the note, and this site does not provide one.

This page is the linked pack hunt_brief("clickjacking") returns on the MCP connector. Authorized testing only.