Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — Basic clickjacking with CSRF token protection (Apprentice) · 🇬🇧
- PortSwigger — Clickjacking with a frame buster script (Apprentice) · 🇬🇧
- PortSwigger — Clickjacking with form input data prefilled from a URL parameter (Apprentice) · 🇬🇧
- PortSwigger — Exploiting clickjacking vulnerability to trigger DOM-based XSS (Practitioner) · 🇬🇧
- PortSwigger — Multistep clickjacking (Practitioner) · 🇬🇧
Curated resources
PortSwigger labs practicing Clickjacking (5)
← Back to the full glossary Last updated: 2026-08-13