S 4.406 Prevention of clickjacking

Initiation responsibility: Head of Development, Persons responsible for individual applications

Implementation responsibility: Developer, Administrator

If the web application is the target of a clickjacking attack, then the contents of the web application are integrated into an invisible frame. If a user visits a website into which this frame has been integrated, then clicks on visible contents are intercepted by an invisible frame without being noticed by the user. If the user is logged in on the web application, then access-protected actions can thus be carried out in the web application in an unauthorised manner. To prevent this, the web application must ensure that the contents of its own web application are not used in frames.

Therefore, the following countermeasures to prevent clickjacking should be implemented:

Review questions: