We are still vulnerable to clickjacking attacks: About 99% of Korean websites are dangerous

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Scopus citations

Abstract

Clickjacking is an attack that tricks victims into clicking on invisible elements of a web page to perform an unintended action that is advantageous for an attacker. To defend against clickjacking, many techniques have already been proposed, but it is still unclear whether they are effectively deployed in practice. We study how vulnerable Korean websites are to clickjacking attacks by performing real attacks on top 100 popular Korean websites as well as all the financial websites. Our results are quite significant: almost all Korean websites (about 99.2 %) that we looked at are vulnerable to clickjacking attacks. Extending our observation to mobile websites, we can also obtain similar results.

Original languageEnglish
Title of host publicationInformation Security Applications - 14th International Workshop, WISA 2013, Revised Selected Papers
PublisherSpringer Verlag
Pages163-173
Number of pages11
ISBN (Print)9783319051482
DOIs
StatePublished - 2014
Event14th International Workshop on Information Security Applications, WISA 2013 - Jeju Island, Korea, Republic of
Duration: 19 Aug 201321 Aug 2013

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume8267 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference14th International Workshop on Information Security Applications, WISA 2013
Country/TerritoryKorea, Republic of
CityJeju Island
Period19/08/1321/08/13

Fingerprint

Dive into the research topics of 'We are still vulnerable to clickjacking attacks: About 99% of Korean websites are dangerous'. Together they form a unique fingerprint.

Cite this