Unsystematic literature review

Context

Iframes are used to enhance the process of displaying data dynamically on the browser. Vulnerability in iframes has enabled attackers to place a hidden layer on top of a victim site and to either load another page or to place ads inside the target website.

By clicking on something that might look interesting and/or trustworthy, victims end up clicking on the hidden layer of iframes (clickjacking), luring them into either liking a page on Facebook or posting a status for a site they didn’t intend to, or possibly downloading a malware (drive-by download)

Our objective in this paper is to demonstrate the dangers of using iframes and present a mean of security to protect clients from such attacks.


References