Clickjacking and framing policy
A framed page is a finding only when a click still completes a state change. Read the framing headers, name the action, and stop. Do not publish a frame.
Tags: clickjacking, csp, framing
Level: intermediate
Method
Pick a state-changing page
Choose one action on an account you own: confirm a payment, change a role, disable a factor, or accept an invite. A static article with no action is not the target.
Tools: browser
Read the framing policy
Record Content-Security-Policy frame-ancestors and X-Frame-Options on that response, including the error page. A policy on the homepage does not cover the action.
Tools: Burp Suite
Name the click
Write the control the user would have to click, and what the server stores if that click lands. The missing header is the primitive. The stored change is the impact.
Tools: browser
Stop without a hosted frame
Describe the page, the headers, and the action. A public frame page is not required, and it can put a real user through the action. Do not ship one.
Tools: browser
Field notes
- frame-ancestors 'self' and X-Frame-Options DENY are different headers. Record the one the response actually sent.
- A missing header on a page with no state change is usually informational.
- SameSite cookies do not replace a framing policy.