Clickjacking is also known as redressing or IFRAME overlay. The name was coined from click hijacking, and the technique is most often applied to web pages by overlaying malicious content over a trusted page or by placing a transparent page on top of a visible one. There is a clickjacking vulnerability in a very critical page which is the admin info page. In essence, the attacker has "hijacked" the user's click, hence the name "Clickjacking".

Clickjacking Vulnerability

The vulnerability can be fixed by adding "frame-ancestors 'self';" to the CSP (Content-Security-Policy) header. Attacker may tricked user, sending them malicious link then user open it clicked some image and their account unconsciously has been deactivated HackerOne helps organizations reduce the risk of a security incident by working with the world's largest community of hackers. The idea is very simple. In my case the vulnerable page was login page. ClickJacking issue I discovered that have some endpoints that permits to frame with some limitations, but even in this case, it is possible to carry out a proof of concept. As hackers submit vulnerability reports through the HackerOne platform, their reputation measures how likely their finding is to be immediately relevant and actionable. The Coinbase Bug Bounty Program enlists the help of the hacker community at HackerOne to make Coinbase more secure. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending on the architecture of the underlying system. Consider the following example: A web user accesses a decoy website. Mostly the companies are not accepting the clickjacking vulnerability, If the impact is not high. The Kubernetes Bug Bounty Program enlists the help of the hacker community at HackerOne to make Kubernetes more secure. Harvest login credentials, by rendering a fake login box on top of the real one. HackerOne is the #1 hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminally exploited. The victim tries to click on the "free iPod" button but instead actually clicked on the invisible "delete all messages" button. Sites can use this to avoid clickjacking attacks, by ensuring that their content is not embedded into other sites. The admin info page of all installations would be vulnerable. Clickjacking (User Interface redress attack, UI redress attack, UI redressing) is a malicious technique of tricking a Web user into clicking on something different from what the user perceives they are clicking on, thus potentially revealing confidential information or taking control of their computer while clicking on seemingly innocuous web pages. The X-Frame-Options HTTP response header can be used to indicate whether or not a browser should be allowed to render a page in a frame or iframe.