Recent trends in client-focused attacks have been focused on circumventing many trusted protection mechanisms and heightening user awareness. While I will not cover these in great detail, it is worth noting their potential and thinking about how to both evaluate and exploit these vulnerabilities as needed in your own testing.
Trendy hacks come and go
Clickjacking (bWAPP)
Clickjacking was a prevalent attack method a few years ago that was notable for its use across Facebook, Twitter, Amazon, and other prominent sites. In all of these attacks, hackers tricked users into clicking on a masqueraded or hidden link to launch a malicious page or script. Simple HTML was capable of providing an overlapping iFrame or other mechanism...