Web Hack List

Collected research

Busting Frame Busting: a Study of Clickjacking Vulnerabilities on Popular Sites

A survey of frame-busting JavaScript across the Alexa top 500 found only 14% deploy any, and every deployment could be circumvented. The attacks include double framing to make parent.location a security violation, onBeforeUnload with 204 flushing, inducing the IE8 and Chrome XSS filters to disable the busting script, and location clobbering. A style-hides-body defence is proposed.

Record

Researcher
Gustav Rydstedt, Elie Bursztein, Dan Boneh and Collin Jackson
Published by
seclab.stanford.edu
Format
Whitepaper
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Gustav Rydstedt, Elie Bursztein, Dan Boneh and Collin Jackson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .