Clickjacking /framing on sensitive Subdomain
None
S
Sifchain
Submitted None
Actions:
Reported by
ilxax1
Vulnerability Details
Technical details and impact analysis
Vulnerability Name : Clickjacking /framing
Vulnerability Description : Clickjacking is an interface-based attack in which user is tricked into clicking on actionable content on a hidden website by
clicking on some other content in a decoy website .
Vulnerable Url : https://cryptoeconomics.sifchain.finance/
. Steps to reproduce :
1 - copy the url : https://cryptoeconomics.sifchain.finance/#sif10jatqfd88m8s2uhtdtdl3txtayjtzsve2klyhh&type=lm
2 - Go to test the vulnerability by using : https://www.lookout.net/test/clickjack.html
$ POC :
. Screenshots .
## Impact
The user assumes that they're entering their information into a usual form but they're actually entering it in fields the hacker has overlaid on the UI. Hackers will target passwords, credit card numbers and any other valuable data they can exploit .
Report Details
Additional information and metadata
State
Closed
Substate
Not-Applicable
Submitted
Weakness
UI Redressing (Clickjacking)