All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

SVG Clickjacking: A New Technique for Advanced Interactive Attacks and Data Exfiltration

By

spartanatreyu

5mo ago· 28 min readenInsight

Summary

The article introduces a novel cybersecurity technique called "SVG clickjacking" that significantly enhances traditional clickjacking attacks. Unlike classic clickjacking which only works for simple button presses, this new method using SVG filters enables complex interactive attacks and multiple forms of data exfiltration. The technique represents a powerful evolution of clickjacking that makes sophisticated attacks more feasible and dangerous.

Key quotes

· 4 pulled
Clickjacking is a classic attack that consists of covering up an iframe of some other website in an attempt to trick the user into unintentionally interacting with it.
I've discovered a new technique that turns classic clickjacking on its head and enables the creation of complex interactive clickjacking attacks, as well as multiple forms of data exfiltration.
I call this technique 'SVG clickjack'
It works great if you need to trick someone into pressing a button or two, but for anything more complicated it's kind of unrealistic.
Snippet from the RSS feed
A novel and powerful twist on an old classic.

You might also wanna read