Burp Suite User Forum

Create new post

Clickjacking labs not working

Jay | Last updated: Jun 12, 2024 02:21PM UTC

I have tried some of the apprentice clickjacking labs in the past and could not complete them even though the payload aligned perfectly. I have now come across this issue again in the lab: Exploiting clickjacking vulnerability to trigger DOM-based XSS. The same issue occurs, I am able to craft the payload and view it, with the text aligning perfectly to the button. When the payload is delivered nothing happens - I've tested it on both Chrome and Burp's browser.

Ben, PortSwigger Agent | Last updated: Jun 13, 2024 06:57AM UTC

Hi Jay, There is an issue with carrying out the Clickjacking labs using the embedded browser at this current point in time. These should, however, still work when you use a standard version of Chrome. I have just run through the 'Exploiting clickjacking vulnerability to trigger DOM-based XSS' lab and been able to solve it in standard Chrome - are you able to provide us with details of what exploit you are using and a screenshot of what you see when you use the 'View exploit' functionality?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.