• DocumentCode
    3310086
  • Title

    Practical clickjacking with BeEF

  • Author

    Lundeen, B. ; Alves-Foss, Jim

  • Author_Institution
    Center for Secure & Dependable Syst., Univ. of Idaho, Moscow, ID, USA
  • fYear
    2012
  • fDate
    13-15 Nov. 2012
  • Firstpage
    614
  • Lastpage
    619
  • Abstract
    A lot of effort has been put into researching client-side attacks, including vulnerabilities like cross-site scripting, cross-site request forgery, and more recently, clickjacking. Similar to other client-side attacks, a clickjacking vulnerability can use the browser to exploit weaknesses in cross domain isolation and the same origin policy. It does this by tricking the user to click on something that is actually not what the user perceives they are clicking on. In the most extreme cases, this vulnerability can cause an unsuspecting user to have their account compromised with a single click. Although there are protections available for clickjacking, the web applications implementing these mitigations are far and in between. Additionally, although the possibility for an attacker to frame a page is easy to detect, it is much more difficult to demonstrate or assess the impact of a clickjacking vulnerability than more traditional client-side vectors. Tools do not currently exist to reliably demonstrate clickjacking exploitation, and the rare demonstrations that are done typically use custom JavaScript and HTML for each individual vulnerability. Worse, many times this esoteric code is never made public, leaving everyone to rewrite their own from scratch. BeEF, known as the Browser Exploitation Framework, is a tool designed to help professional penetration testers easily demonstrate the impact of client-side security vulnerabilities. In this paper, we present a plugin module for BeEF which provides a way for penetration testers to easily demonstrate the impact of clickjacking vulnerabilities.
  • Keywords
    Internet; Java; hypermedia markup languages; security of data; BeEF; HTML; JavaScript; Web applications; browser exploitation framework; clickjacking exploitation; client side attacks; client side vectors; cross site request forgery; cross site scripting; esoteric code; practical clickjacking; Browsers; Cascading style sheets; Facebook; HTML; Internet; Security; Vectors; formatting; insert; style; styling;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Homeland Security (HST), 2012 IEEE Conference on Technologies for
  • Conference_Location
    Waltham, MA
  • Print_ISBN
    978-1-4673-2708-4
  • Type

    conf

  • DOI
    10.1109/THS.2012.6459919
  • Filename
    6459919