XSRF or clickjacking with no practical use to attackers