
WEIGHT: 52 kg
Bust: Medium
1 HOUR:140$
Overnight: +90$
Services: Parties, Hand Relief, Travel Companion, Moresomes, 'A' Levels
Clickjacking attacks are an emerging threat on the web. In this paper, we design new clickjacking attack variants using existing techniques and demonstrate that existing clickjacking defenses are insufficient.
We observe the root cause of clickjacking is that an attacker application presents a sensitive UI element of a target application out of context to a user such as hiding the sensitive UI by making it transparent , and hence the user is tricked to act out of context.
To address this root cause, we propose a new defense, InContext , in which web sites or applications mark UI elements that are sensitive, and browsers or OSes enforce context integrity of user actions on these sensitive UI elements, ensuring that a user sees everything she should see before her ac- tion and that the timing of the action corresponds to her intent.
We have conducted user studies on Amazon Mechanical Turk with participants to evaluate the effectiveness of our attacks and our defense. Papers and proceedings are freely available to everyone once the event begins. Download Audio. Clickjacking: Attacks and Defenses. Huang PDF. View the slides. Presentation Video.