vulns.co
/
GKData.io MCP

Back to Playbooks

Clickjacking and framing policy

A framed page is a finding only when a click still completes a state change. Read the framing headers, name the action, and stop. Do not publish a frame.

Tags: clickjacking, csp, framing

Level: intermediate

Method

  1. Pick a state-changing page

    Choose one action on an account you own: confirm a payment, change a role, disable a factor, or accept an invite. A static article with no action is not the target.

    Tools: browser

  2. Read the framing policy

    Record Content-Security-Policy frame-ancestors and X-Frame-Options on that response, including the error page. A policy on the homepage does not cover the action.

    Tools: Burp Suite

  3. Name the click

    Write the control the user would have to click, and what the server stores if that click lands. The missing header is the primitive. The stored change is the impact.

    Tools: browser

  4. Stop without a hosted frame

    Describe the page, the headers, and the action. A public frame page is not required, and it can put a real user through the action. Do not ship one.

    Tools: browser

Field notes

  • frame-ancestors 'self' and X-Frame-Options DENY are different headers. Record the one the response actually sent.
  • A missing header on a page with no state change is usually informational.
  • SameSite cookies do not replace a framing policy.

References