Clickjacking is an attack in which the attacker overlays a custom-made attack page on a legitimate website or web page. Consider the same scenario as mentioned in the case of the CSRF attack. The web page that can delete all the users can be made transparent in such a way that the buttons on the page are not visible to the user. What is visible, therefore, is an attack page below the transparent layer of a legitimate web page. An attacker can craft a web page, for example, that displays iPhone offers and that might have a button that says win iPhone now placed under the transparent button delete all users. Thus, when a victim, the admin user, thinks they are clicking on a win iPhone button, they are actually clicking on the transparent button that deletes all users from the database.
One of the ways for a website to prevent itself from Clickjacking is by implementing...