In association with heise online

That's not Clickjacking at all! 29 January 2009 14:14

That "security expert" either cannot understand Clickjacking, or he's
purposely using the buzzword to get some cheap publicity.
His "PoC" is just an laughably over-elaborated version of a simple:

<a href="http://yahoo.com"
onclick="location='http://xssed.com';return false">Yahoo</a>

That's not Clickjacking by any stretch of imagination, and hardly
malicious: you just get on a "surprise" destination, but nothing more
since it can't do any of the cross-site evils (e.g. bypassing CSRF
protection) of the real thing.

The H open source

The H Security

The H Internet Toolkit