From 85b9417317fd3c2191dbc3337963d667be6bba83 Mon Sep 17 00:00:00 2001 From: longo-andrea Date: Fri, 26 Mar 2021 20:58:30 +0100 Subject: [PATCH 1/3] The clickjacking attack --- .../06-clickjacking/article.md | 144 +++++++++--------- .../clickjacking-visible.view/index.html | 2 +- .../clickjacking.view/index.html | 2 +- 3 files changed, 74 insertions(+), 74 deletions(-) diff --git a/3-frames-and-windows/06-clickjacking/article.md b/3-frames-and-windows/06-clickjacking/article.md index 1daa87dd0..fb3e2e917 100644 --- a/3-frames-and-windows/06-clickjacking/article.md +++ b/3-frames-and-windows/06-clickjacking/article.md @@ -1,33 +1,33 @@ -# The clickjacking attack +# L'attacco clickjacking -The "clickjacking" attack allows an evil page to click on a "victim site" *on behalf of the visitor*. +L'attacco "clickjacking" consente ad una pagina maligna di cliccare su un "sito vittima" *per conto dell'utente*. -Many sites were hacked this way, including Twitter, Facebook, Paypal and other sites. They have all been fixed, of course. +Molti siti hanno subito attacchi di questo tipo, inclusi Twitter, Facebook, Paypal e molti altri. Ovviamente, il problema in questi siti è stato risolto. -## The idea +## L'idea -The idea is very simple. +L'idea è piuttosto semplice. -Here's how clickjacking was done with Facebook: +Il clickjacking nel caso di Facebook funzionava in questo modo: -1. A visitor is lured to the evil page. It doesn't matter how. -2. The page has a harmless-looking link on it (like "get rich now" or "click here, very funny"). -3. Over that link the evil page positions a transparent `