Difference between revisions of "Clickjacking"
Jump to navigation
Jump to search
| Line 11: | Line 11: | ||
* [[HTTP headers]]: <code>[[Content-Security-Policy]]</code> | * [[HTTP headers]]: <code>[[Content-Security-Policy]]</code> | ||
* [[HSTS]] | * [[HSTS]] | ||
| + | * [[X-Frame-Options]]: DENY | ||
== See also == | == See also == | ||
Revision as of 12:12, 6 May 2026
Clickjacking is an attack that tricks a user into clicking a webpage element which is invisible or disguised as another element.
Content-Security-Policy: frame-ancestors 'none' Content-Security-Policy: frame-ancestors 'self' Content-Security-Policy: frame-ancestors https://trusted.example.com
Related terms
See also
- HTTP Headers:
Authorization:, X-Frame-Options, Content-Security-Policy, Cache-Control, Terraform:drop_invalid_header_fields - Security: Security portfolio, Security standards, Hardening, CVE, CWE, Wireless Network Hacking, vulnerability scanner, Security risk assessment, SCA, Application Security Testing, OWASP, Data leak, NIST (800-53), SANS, MITRE, Security policy, Access Control attacks, password policy, password cracking, Password manager, MFA, OTP, UTF, Firewall, DoS, Software bugs, MITM, Certified Ethical Hacker (CEH) Contents, Security+ Malware, FIPS, DLP, Network Access Control (NAC), VAPT, SIEM, EDR, SOC, pentest, PTaaS, Clickjacking, MobSF, Janus vulnerability, Back Orifice, Backdoor, CSO, CSPM, PoLP, forensic, encryption, Keylogger, Pwn2Own, CISO, Prototype pollution, dnsrecon, Attack surface, Principle of least privilege (PoLP), Bounty, Linux Kernel security, Local Privilege Escalation (LPE), Secure Product Lifecycle (SPLC), Code signing
Advertising: