首页> 外文会议>Annual Conference on Privacy, Security and Trust >Clickjuggler: Checking for incomplete defenses against clickjacking
【24h】

Clickjuggler: Checking for incomplete defenses against clickjacking

机译:Clickjuggler:检查针对Clickjacking的不完整防御措施

获取原文

摘要

Clickjacking is a new attack which exploits a vulnerability in web applications. It tricks victims into clicking on something different from what they perceive they are clicking on. The victims may reveal confidential information or start unintended online transactions. Clickjacking can be prevented if appropriate countermeasures such as frame busting are implemented in web applications. However, the correct implementation is not easy. A trivial mistake in the implementation leads to evasion of the countermeasures. For the correct implementation, web developers must have intimate knowledge on evasion techniques of the countermeasures. In this paper, we propose Clickjuggler, an automated tool for checking for defenses against clickjacking during the development. Clickjuggler generates clickjacking attacks, performs those attacks on web applications, and checks whether the attacks are successful or not. By automating the process of checking for the clickjacking vulnerabilities, web developers are released from the burden of checking the correctness of their implementation. Unskillful developers can benefit from Clickjuggler since no special knowledge on clickjacking is needed to use Clickjuggler. Our experimental results demonstrate that Clickjuggler can check for the clickjacking vulnerabilities in 4 real-world web applications.
机译:Clickjacking是一种利用Web应用程序中的漏洞的新型攻击。它诱使受害者点击与他们认为自己点击的东西不同的东西。受害者可能会泄露机密信息或开始意外的在线交易。如果在Web应用程序中实施了诸如帧清除之类的适当对策,则可以防止点击劫持。但是,正确的实施并不容易。实施中的一个小错误导致对策的回避。为了正确实施,Web开发人员必须对对策的规避技术有深入的了解。在本文中,我们提出了Clickjuggler,这是一种自动工具,用于在开发过程中检查对点击劫持的防御。 Clickjuggler生成clickjacking攻击,对Web应用程序执行这些攻击,并检查攻击是否成功。通过自动化检查点击劫持漏洞的过程,Web开发人员从检查其实现的正确性的负担中解放了出来。不熟练的开发人员可以从Clickjuggler中受益,因为使用Clickjuggler不需要有关Clickjacking的专门知识。我们的实验结果表明,Clickjuggler可以检查4个实际Web应用程序中的clickjacking漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号