References:
- https://auth0.com/blog/preventing-clickjacking-attacks/
- https://cheatsheetseries.owasp.org/cheatsheets/Clickjacking_Defense_Cheat_Sheet.html
Attacker's website contains an iframe with your site in it which sits on top of the attacker's website but invisible to the user (opacity: 0
). The user then unknowingly interacts with your website and might click a like or purchase button.