Explore tweets tagged as #Clickjacking
@jatav_ravi
Archer
2 days
Found a Clickjacking vulnerability accepted as Critical Severity! . By chaining it with an invite/token flow, it led to full Account Takeover. Now just waiting on that bounty drop . #BugBounty #CyberSecurity #Clickjacking #AccountTakeover
Tweet media one
10
4
100
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
7 days
The Ultimate Double-Clickjacking POC
0
2
46
@J0R1AN
Jorian
2 months
Double-Clickjacking, or "press buttons on other sites without preconditions". After seeing and experimenting with this technique for a while, I cooked up a variation that combines many small tricks and ends up being quite convincing. Here's a flexible PoC:.
2
48
201
@jssodhi
Prof (Dr) JSSodhi
3 days
Tweet media one
0
0
3
@havocgwen
Guhan Raja
9 months
Found an injection vulnerability in a familiar @Google subdomain that allows me to frame any external website within the page. This vulnerability bypasses Google’s same-origin policy (SOP), creates potential risks like clickjacking and phishing attacks.
Tweet media one
12
25
451
@atomicbyte_
AtomicByte
2 months
I creating a thingy called clipjacking imagine getting hacked by copying text on a website. It's basically clickjacking but better. Repost and follow or I'll steal your NFTs >:3.
2
14
50
@vivekramac
Vivek Ramachandran
6 months
Double Clickjacking is the new attack kid on the block - Here's a good article on Forbes by Davey Winder This subverts most existing browser-based protections like X-Frame-Options simply because it's a clever UI redressing attack. Also, the attack's
0
8
19
@ccfis
CCFIS
3 days
Tweet media one
0
0
3
@Anastasis_King
Cyberkid
2 months
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
0
1
@vahidnameni
🛡VAHID NAMENI☣️
6 months
تقریباً عملیاتی کردن Clickjacking با وجود مکانیزم‌های مدرن مرورگرها مثل SameSite: Lax ناممکن است. ⚠️ اما حالا شاهد بوجود آمدن DoubleClickjacking هستیم!. برخلاف Clickjacking سنتی که به یک کلیک تکیه دارد، DoubleClickjacking از یک توالی دو کلیک بهره‌برداری می‌کند. 🔓 این تغییر
Tweet media one
0
1
24
@jatav_ravi
Archer
2 months
Just scored a bounty for Clickjacking at Auth Pages. Login, Signup, and Reset Password pages. These bugs may be small, but they add extra zeros to your bank account! .#BugBounty #Infosec
Tweet media one
3
1
47
@_0x999
0x999 🇮🇱
4 months
Yay, I was awarded a $5,050 bounty for Clickjacking -> ATO + $7,700 for several other bugs which I’m excited to write about once they’re cleared for disclosure🤞 #TogetherWeHitHarder
Tweet media one
Tweet media two
Tweet media three
9
15
222
@CareWeDoNot
WDNC
3 months
🔍 Appknox found 10 high-risk bugs in Perplexity AI’s Android app — more than even DeepSeek. ⚠️ Issues include hardcoded API keys, no SSL, clickjacking, old Android vulns & CORS flaws. Easy to exploit, risking user data. 📵 Users urged to uninstall ASAP.
Tweet media one
2
0
7
@reverseame
reverseame
15 days
0
2
6
@impratikdabhi
Pratik Dabhi
25 days
🛡️ 5 Easy-to-Exploit Misconfigurations. • Open Redirect: ?next= or ?url=.• CORS with * + credentials.• Host Header Injection.• Clickjacking (no X-Frame-Options).• Exposed files: .git, .env, .DS_Store. 📉 Misconfigs = $$$ in bug bounty!.#BugBounty #InfoSec #WebSecurity.
1
5
51
@trshpuppy
૮ ・ ﻌ・ა Trash Puppy
5 months
This thirst trap brought to you by clickjacking.
Tweet media one
20
1
120
@Commanak46
Monika Sharma
2 months
Discovered a $3,000 RCE vuln in Burp Suite! chained Chrome debug port, clickjacking, and JVM tricks to execute OS commands. 🔍 Learn how debug interfaces can be exploited in this detailed write-up.
3
39
144
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
1 month
HackerNotes TLDR for episode 125! — ►⠀Double Clickjacking POC: This research from Jorian leverages browser APIs ( moveTo), pop-unders, and a fake Google Sign-In prompt to invisibly chase a user's cursor and steal a critical.
0
5
27
@stilla1ex
alex
1 month
What is clickjacking attack?
Tweet media one
2
9
58