Cross-Site Framing Attacks

Nethanel Gelernter, Yoel Grinstein, Amir Herzberg · 2015

We identify the threat of cross-site framing attacks, which involves planting false evidence that incriminates computer users, without requiring access to their computer. We further show that a variety of framing-evidence can be planted using only modest framing-attacker capabilities. The attacker can plant evidence in both the logs of popular reputable sites and in the computer of the victim, without requiring client-side malware and without leaving traces.

Read the paper · More papers on PaperTik