Dark Mode

Settings

Capec-181 Detail

Flash File Overlay

Detailed Software Typical Severity: Medium

Parents: 103

Description

An attacker creates a transparent overlay using flash in order to intercept user actions for the purpose of performing a clickjacking attack. In this technique, the Flash file provides a transparent overlay over HTML content. Because the Flash application is on top of the content, user actions, such as clicks, are caught by the Flash application rather than the underlying HTML. The action is then interpreted by the overlay to perform the actions the attacker wishes.

Not present

External ID Source Link Description
CAPEC-181 capec https://capec.mitre.org/data/definitions/181.html
CWE-1021 cwe http://cwe.mitre.org/data/definitions/1021.html

Not present

  1. The victim must be tricked into navigating to the attackers' decoy site and performing the actions on the decoy page.
  2. The victim's browser must support invisible Flash overlays.
  1. The attacker must be able to force the Flash overlay over the decoy content.

Not present

Not present

Not present