 Oleg Bellsouth Fastaccess Premium join:2003-12-08 Birmingham, AL
| Security researchers warn of new 'clickjacking' browser bugs
September 26, 2008 (Computerworld) Security researchers warned today that a new class of vulnerabilities dubbed "clickjacking" puts users of every major browser at risk from attack.
Read more »www.computerworld.com/action/art···M&nlid=8 | |
|
 SUMware Premium join:2002-05-21
1 edit | Re: Security researchers warn of new 'clickjacking' browser bugs This is an extremely serious and difficult vulnerability.
Doctor Four and I posted important information about this in a different thread: »Re: Malvertisement on MSNBC.com using clipboard (copy/paste) . Please read it.
Giorgio Maone, the creator of NoScript, "had access to detailed information about how this attack works". He said "I was told that it's indeed "very, freaking scary" and "near impossible" to fix properly."
swhx7 added this:
said by swhx7 :The discoverers have been vague about just what the "clickjacking" involves. The reason of course is the same as in the recent Kaminsky/DNS thing, to give vendors time to patch. This has led to some anxiety about how site maintainers and surfers can be safe. In looking around however, I found a clear explanation of at least one implementation of it: » lists.whatwg.org/pipermail/whatw···284.htmlThe above is already out there, so I'm not making it any worse by linking. I favor Zalewski's #4, because it puts the user most in control. Oleg, glad that you've started a dedicated thread for this. | |
|
 |  |
 |  |  mysec Premium join:2005-11-29 3 edits | Re: Security researchers warn of new 'clickjacking' browser bugs n/m | |
|
 redwolfe_98
join:2001-06-11 1 edit | i don't see how this "click-jacking" issue could be much of a problem.. | |
|
 |   JohnInSJ Premium join:2003-09-22 San Jose, CA
·Comcast
| Re: Security researchers warn of new 'clickjacking' browser bugs said by redwolfe_98 :i don't see how this "click-jacking" issue could be much of a problem.. I guess it depends on if you hang out at compromised sites, while having important authenticated content open in another window at the same time, while madly clicking on everything you can (or maybe cannot) see. | |
|
 |   Dude111 An Awesome Dude Premium join:2003-08-04 USA | Just as i thought this is nothing........ (Only people that dont know what they are doing might be affected) | |
|
 |
 |
  nwrickert sand groper Premium,MVM join:2004-09-04 Geneva, IL
·AT&T U-Verse
·AT&T Midwest
| Interesting. Thanks.
For some time, now, I have been using multiple firefox profiles. Banking, router configuration, etc, uses one profile. Ordinary browsing uses another. This separation should greatly reduce the risk from all kinds of cross site vulnerabilities.
So, sure, a clever cross site attack might change my dslr profile, but it could not change my router configuration nor could it do something with my bank account. -- AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.3 | |
|
  Dude111 An Awesome Dude Premium join:2003-08-04 USA | I saw a demo of this and it just looks like an overlay of a page and the browsers unablity to seperate the 2 pages allows the exploit.....
Demo > »www.youtube.com/v/gxyLbpldmuU | |
|
 |
 |
|
 |