Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Security researchers warn of new 'clickjacking' browser bugs
Search Topic:
Uniqs:
1172
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Security Software Updates - 08 Oct 2008 »
« MS update KB951748 and ZoneAlarm --- PROBLEM  
AuthorAll Replies
-


NanDog
The Pup Was Female, I'M Not
Premium
join:2003-12-28
Tacoma, WA
reply to Oleg
Re: Security researchers warn of new 'clickjacking' browser bugs

This even made Yahoo's front page today: »news.yahoo.com/s/nf/20081008/bs_nf/62355
--
See ya across the Rainbow Bridge, my good and faithful friend!


Dude111
An Awesome Dude
Premium
join:2003-08-04
USA
reply to Oleg
I saw a demo of this and it just looks like an overlay of a page and the browsers unablity to seperate the 2 pages allows the exploit.....

Demo > »www.youtube.com/v/gxyLbpldmuU


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
·AT&T U-Verse
·AT&T Midwest

reply to Oleg
Interesting. Thanks.

For some time, now, I have been using multiple firefox profiles. Banking, router configuration, etc, uses one profile. Ordinary browsing uses another. This separation should greatly reduce the risk from all kinds of cross site vulnerabilities.

So, sure, a clever cross site attack might change my dslr profile, but it could not change my router configuration nor could it do something with my bank account.
--
AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.3

SUMware
Premium
join:2002-05-21
reply to Oleg
Firefox users can avail themselves of NoScript: »NoScript Fights Clickjacking


swhx7
Premium
join:2006-07-23
Elbonia
·RoadRunner Cable

reply to Oleg
Details are public now. »ha.ckers.org/blog/20081007/click···details/

More: »securosis.com/2008/10/07/clickja···-advice/


Dude111
An Awesome Dude
Premium
join:2003-08-04
USA
reply to redwolfe_98
Just as i thought this is nothing........ (Only people that dont know what they are doing might be affected)

mysec
Premium
join:2005-11-29

3 edits
reply to ravencajun
n/m


ravencajun
Premium
join:2004-08-12
Houston, TX

reply to SUMware
Oleg, glad that you've started a dedicated thread for this.

times 2!
I was going to start one a few days ago then found the other threads mentioned.
These were some of the other articles recently, might as well put them all in one spot.
Clickjacking: Researchers raise alert for scary new cross-browser exploit
Firefox + NoScript vs Clickjacking
Adobe Flash ads launching clipboard hijack attack
copy and paste from the ubuntu forums.

It is definitely a topic that needs attention.
Some of the scenarios that have been mentioned are pretty scary.
Hopefully something constructive will come out of the discussions and a fix is on the horizon.


JohnInSJ
Premium
join:2003-09-22
San Jose, CA
·Comcast

reply to redwolfe_98
said by redwolfe_98 See Profile :

i don't see how this "click-jacking" issue could be much of a problem..
I guess it depends on if you hang out at compromised sites, while having important authenticated content open in another window at the same time, while madly clicking on everything you can (or maybe cannot) see.

redwolfe_98

join:2001-06-11

1 edit
reply to Oleg
i don't see how this "click-jacking" issue could be much of a problem..

SUMware
Premium
join:2002-05-21


1 edit
reply to Oleg
This is an extremely serious and difficult vulnerability.

Doctor Four and I posted important information about this in a different thread: »Re: Malvertisement on MSNBC.com using clipboard (copy/paste) . Please read it.

Giorgio Maone, the creator of NoScript, "had access to detailed information about how this attack works". He said "I was told that it's indeed "very, freaking scary" and "near impossible" to fix properly."

swhx7 added this:
said by swhx7 See Profile :

The discoverers have been vague about just what the "clickjacking" involves. The reason of course is the same as in the recent Kaminsky/DNS thing, to give vendors time to patch. This has led to some anxiety about how site maintainers and surfers can be safe.

In looking around however, I found a clear explanation of at least one implementation of it: »lists.whatwg.org/pipermail/whatw···284.html

The above is already out there, so I'm not making it any worse by linking.

I favor Zalewski's #4, because it puts the user most in control.
Oleg, glad that you've started a dedicated thread for this.


Oleg
Bellsouth Fastaccess
Premium
join:2003-12-08
Birmingham, AL

  September 26, 2008 (Computerworld) Security researchers warned today that a new class of vulnerabilities dubbed "clickjacking" puts users of every major browser at risk from attack.

Read more »www.computerworld.com/action/art···M&nlid=8
Forums » Up and Running » Security » SecuritySecurity Software Updates - 08 Oct 2008 »
« MS update KB951748 and ZoneAlarm --- PROBLEM  


Thursday, 10-Dec 08:21:12 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [200] Sprint Sued For Distracted Driving Death
· [120] AT&T Launching New 24 Mbps U-Verse Tier
· [82] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [68] AT&T Hints At Usage-Based iPhone Data Pricing
· [66] Sprint Poised For A Turnaround?
· [66] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [51] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [45] Microwaving Your Innards Is Not 'Extreme'
Most people now reading
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Cross Server Dungeon Experience [World of Warcraft]
· Comcast refused to install 400' feet. [Comcast HSI]
· Lawyers Claim Palin Hack Suspect's PC Had Spyware [Security]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Windows 7 boot manager editing questions [Microsoft Help]
· Battered Hilt Delimma [World of Warcraft]
· Icecrown 5-man strats [World of Warcraft]
· [game] CG6 - Gunslinger - Day 1 [Pub Games]