TL;DR
Clickjacking is a cyberattack technique where hidden layers trick users into performing unintended actions, such as downloading malware, transferring money, or liking social media pages. Attacks range from classic iframe overlays to cursorjacking and filejacking. Both consumers and developers can defend against clickjacking using tools like X-Frame-Options headers, browser extensions such as NoClickJack or NoScript, and keystroke encryption software like GuardedID.
How does clickjacking happen?
Clickjacking occurs when a hacker hides hyperlinks behind the content visible to users in order to steal clicks.
A clickjacking attack begins with deception. You encounter a form, button, or another item you can manipulate. Clicking on that item results in an action you never intended.
For example, you're shown a popup screen on a website, and a large button says, "Click to close this window." When you tap that button, you're also liking the company's Facebook page, even though you never intended to do so.
Clickjacking attacks can cause you to:
- Download malware
- Hand out protected information
- Transfer money
- Purchase products
- Offer unwanted social proof
As a consumer, it's important to understand how these attacks work and how you can protect yourself. As an IT professional, it's critical to build sites that are resistant to common clickjacking approaches.
What is clickjacking?
A hacker creates an innocent-seeming web page, button, or form. Multiple layers make up the item. The version you see seems innocent enough. But a layer beneath holds code that can harm you.
Consider this real-world clickjacking example from Facebook:
- Bait. Developers created a web page filled with funny pictures, and they encouraged people to click through to see them.
- Hook. When visitors hit the page, they saw a screen asking them to confirm they were at least 16 years old.
- Switch. Clicking "yes" allowed the people to enter the site. But they also posted a link to the content on their Facebook wall at the same time.
In this example, people didn't intend to share the post on Facebook. But the attack hijacked their click on "yes."
This visual diagram explains how the concept works.
How does clickjacking work?
Layers, deception, and programming allow for clickjacking attacks. Unfortunately, the technique is common. Analysts say two-thirds of the top 20 banking sites are susceptible to this form of hack.
Common clickjacking techniques include:
| Technique Name | How It Works | Primary Risk |
|---|---|---|
| Browserless | Hackers use mobile devices to execute an attack. A tiny delay between a person's action and the server response allows for manipulation. | Manipulation via mobile device timing delays |
| Classic | Hidden layers on web pages take over a user's actions. | Unintended clicks on concealed page elements |
| Cookiejacking | A user interacts with a seemingly harmless object, and the hacker gains access to the user's cookies from all applicable web browsers. | Exposure of cookie data, which can be devastating as cookies hold a great deal of data |
| Cursorjacking | A hacker changes the way a cursor operates. | Hacker could gain access to the user's camera in the ensuing chaos |
| Filejacking | The hacker gains deep control of your device. | Device turned into a file server |
| Likejacking | The hacker tricks you into liking a Facebook or other social media account. | Unwanted social proof and account engagement |
The code behind clickjacking is sophisticated. These attacks aren't created or executed by amateurs.
The best clickjacking attacks are also invisible to the user, so you may never know that anyone has control of your device, your data, or both until it's too late.
How can you prevent clickjacking attacks?
You want every action you take on a website to be meaningful and useful. And as a designer, you want your visitors to trust you and your work. Using prevention tools can help you achieve both goals.
Block clickjacking attacks with:
- Secure browsers. Some companies are building tight, tailored programs that eliminate common clickjacking risks. Research which browsers take this threat into account. And as a designer or developer, make sure your sites work in these alternate browsers.
- Framekiller. Use this JavaScript tool on your web pages to ensure that third parties can't steal your clicks.
- GuardedID. Billed as "keystroke encryption software," GuardedID aims to eliminate clickjacking. The software works on both personal computers (PCs) and Macs.
- Intersection Observer. This Application Programming Interface (API) makes click actions visible, so people have the information they need to make smart decisions online.
- Browser extensions. Customers can use NoClickjack in Chrome or NoScript in Firefox to eliminate attacks as they browse the web.
- X-Frame-Options. Use this Hypertext Transfer Protocol (HTTP) header as you design your website. Tell the browser whether the page should be rendered as a frame, iframe, embed, or object.
Which prevention approach is most effective?
Developers and consumers argue over which approach is most effective. Some swear by X-frames, for example, as they believe prevention should come from developers and not consumers. But others say X-frames come with too many limitations to be effective. Savvy coders can work around almost any obstacle.
In the end, combining your tools and encouraging your customers to be alert about the sites they visit and the work they do online is the best way to block hackers before they take over.
More Security Options Through Okta
Ensure that you give your employees a safe space for their electronic work. Use our platform to manage logins, authentication, and authorization.
Frequently asked questions
What is the difference between clickjacking and phishing?
While phishing typically deceives users through misleading links or fake websites that prompt them to voluntarily hand over information, clickjacking works by hiding malicious actions beneath innocent-looking content. In a clickjacking attack, the user interacts with what appears to be a legitimate button or form, but a hidden layer beneath executes an entirely different action without the user's knowledge.
What types of actions can a clickjacking attack cause?
Clickjacking attacks can lead to a wide range of harmful outcomes. Victims may unknowingly download malware, hand out protected information, transfer money, purchase products, or offer unwanted social proof — all without ever intending to take those actions.
What is cookiejacking and why is it dangerous?
Cookiejacking is a type of clickjacking attack in which a user interacts with a seemingly harmless object, allowing the hacker to gain access to the user's cookies from all applicable web browsers. Because cookies hold a great deal of data, this type of attack can be particularly devastating.
How does X-Frame-Options help prevent clickjacking?
X-Frame-Options is a Hypertext Transfer Protocol (HTTP) header that developers can use when designing a website. It instructs the browser whether the page should be rendered as a frame, iframe, embed, or object, helping to prevent third parties from embedding the page within hidden layers that could be used for clickjacking.
Can browser extensions protect against clickjacking?
Yes, browser extensions can provide an additional layer of protection. Customers can use NoClickjack in Chrome or NoScript in Firefox to help eliminate clickjacking attacks as they browse the web.
Why are banking websites particularly vulnerable to clickjacking?
Analysts have found that two-thirds of the top 20 banking sites are susceptible to clickjacking. Banking sites are attractive targets because they involve financial transactions and sensitive personal data, making them high-value destinations for hackers looking to exploit hidden-layer techniques.
References
The Clickjacking Bug That Facebook Won't Fix. (December 2018). Bleeping Computer.
Clickjacking Threatens Two-Thirds of Top 20 Banking Sites. (November 2020). Infosecurity.
Framekiller. PC.
GuardedID. Strikeforce.
Trust is Good, Observation Is Better: Intersection Observer v2. (February 2021). Web.Dev.
NoClickJack. Chrome Web Store.
No Script. Inform Action Open Source Software.
X-Frame Options. Mozilla.
Clickjacking Attack on Facebook: How a Tiny Attribute Can Save the Corporation. (January 2019). Security Boulevard.