Malware
Clickjacking
Also called UI redress.
Clickjacking is tricking someone into clicking a control they cannot see by stacking your page under a transparent or disguised frame. The visitor thinks they are pressing one button and press another.
How it is measured
Test whether your page can be framed. Load it in an iframe from a different origin; if it renders, it is open to clickjacking. Check for `X-Frame-Options: DENY` or `SAMEORIGIN`, or a CSP `frame-ancestors` directive, in the response headers.
The signal in the wild is a transparent frame, `opacity: 0` or a tiny offset, sitting above a harmless button. Browser dev tools show the overlapping element when you inspect the click target.
Worked example
A fundraising page has a one-click "Confirm donation" button at the bottom. An attacker builds a game page with a "Click to win" button and layers your donation page over it at zero opacity, aligned so the win button sits on top of Confirm. A logged-in donor taps once and a recurring $50 gift is created.
The charity adds `Content-Security-Policy: frame-ancestors 'none'` and the browser refuses to render the page inside any frame, so the trick collapses.
How it differs
Clickjacking hides your real page under a decoy. Iframe injection puts someone else's page into yours. In clickjacking the attacker owns the outer page and frames you. In iframe injection the attacker has broken into your site and plants a frame inside it. The fix for the first is a header; the fix for the second is cleaning the compromised site.
Common errors
Relying on JavaScript frame-busting that can be sandboxed away. Setting `X-Frame-Options` on the homepage but not on account or checkout pages. Forgetting that embeds you want, such as a widget, need a specific allowed ancestor list. Assuming a login page is safe because it needs a password. Skipping the header because the page has no sensitive button.
In practice
Send `frame-ancestors 'self'` on every response by default, and list outside origins only for pages you deliberately embed. Test one sensitive action page by framing it from a local file and confirm the browser blocks it.