Clicking to the Past
Chris Wysopal,
When the first details trickled out about a new attack, dubbed clickjacking by the researchers who found it, the descriptions made me think of the tricks I used to pull during penetration tests ten years ago to get administrator privileges: Tricking the user into issuing a command on an attackers behalf is one of the oldest attack vectors in the book.