Skip to main content
Busting frame busting a study of clickjacking vulnerabilities on popular sites
  1. publications
  2. Cybersecurity

Busting frame busting a study of clickjacking vulnerabilities on popular sites

Available Media Publication (PDF) Slides (PDF)
Conference Web 2.0 Security and Privacy (W2SP) - 2010
Authors Gustav Rydstedt , Elie Bursztein , Dan Boneh ,
Citation BibTeX
BibTeX
@inproceedings{Rydstedt2010Busting,
  title = {Busting frame busting a study of clickjacking vulnerabilities on popular sites},
  author = {Gustav Rydstedt and Elie Bursztein and Dan Boneh and Collin Jackson},
  booktitle = {Web 2.0 Security and Privacy},
  year = {2010},
  organization = {IEEE}
}

Web framing attacks such as clickjacking use iframes to hijack a user’s web session. The most common defense, called frame busting, prevents a site from functioning when loaded inside a frame. We study frame busting practices for the Alexa Top-500 sites and show that all can be circumvented in one way or another. Some circumventions are browser-specific while others work across browsers. We conclude with recommendations for proper frame busting.

newsletter signup
newsletter signup