Performing Clickjacking Attacks in the Wild: 99% are Still Vulnerable!

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Clickjacking is an attack that tricks victims into clicking on invisible elements of a web page to perform unin- tended actions that might be advantageous for the attacker. To defend against clickjacking, many techniques have been proposed, but it is still questionable whether they are effectively deployed in practice. We investigated how vulnerable Korean websites are to clickjacking attacks by performing real attacks on the top 500 most popular Korean websites as well as all of the financial websites. Our results are quite significant: almost all Korean websites (99.6%) that we looked at were vulnerable to clickjacking attacks. Extending our observation to top 500 global websites, we found that 390 of them (78%) were also vulnerable to clickjacking attacks and identified which type of website is particularly insecure against clickjacking.

Original languageEnglish
Title of host publicationProceedings - 2015 1st International Conference on Software Security and Assurance, ICSSA 2015
EditorsJungwoo Ryoo, Hyoungshick Kim
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages25-29
Number of pages5
ISBN (Electronic)9781509010783
DOIs
StatePublished - 10 Jan 2017
Event1st International Conference on Software Security and Assurance, ICSSA 2015 - Suwon, Gyeonggi, Korea, Republic of
Duration: 27 Jul 2015 → …

Publication series

NameProceedings - 2015 1st International Conference on Software Security and Assurance, ICSSA 2015

Conference

Conference1st International Conference on Software Security and Assurance, ICSSA 2015
Country/TerritoryKorea, Republic of
CitySuwon, Gyeonggi
Period27/07/15 → …

Keywords

  • Clickjacking
  • Frame busting
  • Korean websites

Fingerprint

Dive into the research topics of 'Performing Clickjacking Attacks in the Wild: 99% are Still Vulnerable!'. Together they form a unique fingerprint.

Cite this