Collected research
Busting Frame Busting: a Study of Clickjacking Vulnerabilities on Popular Sites
A survey of frame-busting JavaScript across the Alexa top 500 found only 14% deploy any, and every deployment could be circumvented. The attacks include double framing to make parent.location a security violation, onBeforeUnload with 204 flushing, inducing the IE8 and Chrome XSS filters to disable the busting script, and location clobbering. A style-hides-body defence is proposed.
Record
- Researcher
- Gustav Rydstedt, Elie Bursztein, Dan Boneh and Collin Jackson
- Published by
- seclab.stanford.edu
- Format
- Whitepaper
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Gustav Rydstedt, Elie Bursztein, Dan Boneh and Collin Jackson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .