Page tree
Skip to end of metadata
Go to start of metadata

Clickjacking, also known as a "UI redress attack", is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the top level page. Thus, the attacker is "hijacking" clicks, meant for their page and routing them to another page, most likely owned by another application, domain, or both.

Using a similar technique, keystrokes can also be hijacked. With a carefully crafted combination of style sheets, iframes, and text boxes, a user can be led to believe they are typing in the password to their email or bank account, but are instead typing into an invisible frame controlled by the attacker.

A future version of Hybrid Access Gateway will by default implement a protection against this vulnerability. Meanwhile you can follow the instructions to apply the wascr script published with this article, to protect Hybrid Access Gateway against the clickjacking vulnerability.

Expand/Collapse All

Prerequisites

 Prerequisites

Installed Hybrid Access Gateway.

Step-by-step instruction

 Log in to Hybrid Access Gateway administration interface
  1. Log in to the Hybrid Access Gateway administration interface with your admin user.
 Upload script file
  1. In the Hybrid Access Gateway administration interface, click Browse.
  2. Upload the provided script file add_header.wascr (without changing the file name) to access-point/files/custom-files/scripts.

 Add filter
  1. In the Hybrid Access Gateway administration interface, go to Manage Resource Access.
  2. Click Global Resource Settings.
  3. In the Filters tab, click Add Filter...
  4. In Display Name, enter Add X-Frame-Options header. (This name describes the purpose with the filter)
  5. In Script Name, enter add_header.

    The script name must match exactly the name of the script file but without the file suffix .wascr

  6. In Type of Filter, select Response.
  7. In Resource Host, select All resource hosts.
  8. In Path, enter *.
  9. In Apply Filter To, select Header.
  10. Define variable header_name:
    1. Click Add Variable.
    2. In Name, enter header_name
    3. In Value, enter X-Frame-Options
    4. Click Add.
  11. Define variable header_value:
    1. Click Add Variable.
    2. In Name, enter header_value
    3. In Value, enter DENY
    4. Click Add.
  12. Click Add.
  13. Click Save.
  14. Click Publish to apply the settings.

Related information

  • No labels