SoyFinance / smart-contracts

11 stars 9 forks source link

(Bug Report)Click jacking. #17

Open sakshispap opened 11 months ago

sakshispap commented 11 months ago

Vulnerability Name : Click jacking

Target URL:https://soy.finance/

Vulnerability Description : Click jacking (User Interface redress attack, UI redress attack, UI redressing) is a malicious technique of tricking a Web user into clicking on something different from what the user perceives they are clicking on, thus potentially revealing confidential information or taking control of their computer while clicking on seemingly innocuous web pages.

The server didn't return an X-Frame-Options header which means that this website could be at risk of a click jacking attack. The X-Frame-Options HTTP response header can be used to indicate whether or not a browser should be allowed to render a page in a or

2.save it as .html eg s.html

3.and just simply open that..and click on button(direct login) its redirect https://soy.finance/ As far as i know this data is enough to prove that your site is vulnerable to Click jacking.

Impact: Attacker may tricked user, sending them malicious link then user open it clicked some image and their account unconsciously has been deactivated .

Attachment: soy