Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-103 — Clickjacking
CAPEC-103

Clickjacking

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Medium. An adversary tricks a victim into unknowingly initiating some action in one system while interacting with the UI from a seemingly completely different, usually an adversary controlled or intended, system.

Mitigation

If using the Firefox browser, use the NoScript plug-in that will help forbid iFrames. | Turn off JavaScript, Flash and disable CSS. | When maintaining an authenticated session with a privileged target system, do not use the same browser to navigate to unfamiliar sites to perform other activities. Finish working with the target system and logout first before proceeding to other tasks.

Details

Platforms
Social-engineering
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.