Web Hack List

Later archive addition

Busting Frame Busting: a Study of Clickjacking Vulnerabilities on Popular Sites

A survey of frame-busting JavaScript across the Alexa top 500 found only 14% deploy any, and every deployment could be circumvented. The attacks include double framing to make parent.location a security violation, onBeforeUnload with 204 flushing, inducing the IE8 and Chrome XSS filters to disable the busting script, and location clobbering. A style-hides-body defence is proposed.

Record

Researcher
Gustav Rydstedt, Elie Bursztein, Dan Boneh and Collin Jackson
Format
Whitepaper

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Gustav Rydstedt, Elie Bursztein, Dan Boneh and Collin Jackson, first published at the original source. Preserved copies are kept so the citation survives its host.