Page 1 of 1

NoScript Alerts My bank login form as Potential Clickjacking

Posted: Tue May 05, 2009 9:44 pm
by platdrag
url is

https://www.bankhapoalim.co.il/

is it a false positive? or there's something malicous/suspicious out there?

Re: NoScript Alerts My bank login form as Potential Clickjacking

Posted: Tue May 05, 2009 9:59 pm
by Giorgio Maone
It is a false positive due to a bug in the site: the login box is inside an iframe, but rather than being entirely visible is slightly scrolled down therefore some red pixels on the top are hidden.
You can work-around either unlocking or using the arrow keys to scroll up the iframe content.
Anyway nothing malicious there.

Re: NoScript Alerts My bank login form as Potential Clickjacking

Posted: Tue May 05, 2009 10:47 pm
by platdrag
thanks a lot!

i may now sleep in peace :)

(i have sent mail to the site admin, hope they'll fix it)