<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Security researchers warn of new &#x27;clickjacking&#x27; browser bugs in Security</title>
<link>http://www.dslreports.com/forum/r21175031</link>
<description></description>
<language>en</language>
<pubDate>Fri, 04 Dec 2009 02:15:33 EDT</pubDate>
<lastBuildDate>Fri, 04 Dec 2009 02:15:33 EDT</lastBuildDate>

<item>
<title>Re: Security researchers warn of new &#x27;clickjacking&#x27; browser bugs</title>
<link>http://www.dslreports.com/forum/remark,21237566</link>
<description><![CDATA[<A HREF="/useremail/u/921899"><b>NanDog</b></A> : This even made Yahoo's front page today: &raquo;<A HREF="http://news.yahoo.com/s/nf/20081008/bs_nf/62355" >news.yahoo.com/s/nf/20081008/bs_nf/62355</A><br><small>--<br>See ya across the Rainbow Bridge, my good and faithful friend!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21237566</guid>
<pubDate>Wed, 08 Oct 2008 21:54:02 EDT</pubDate>
</item>

<item>
<title>Re: Security researchers warn of new &#x27;clickjacking&#x27; browser bugs</title>
<link>http://www.dslreports.com/forum/remark,21235854</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : I saw a demo of this and it just looks like an overlay of a page and the browsers unablity to seperate the 2 pages allows the exploit.....<br><br>Demo > &raquo;<A HREF="http://www.youtube.com/v/gxyLbpldmuU" >www.youtube.com/v/gxyLbpldmuU</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21235854</guid>
<pubDate>Wed, 08 Oct 2008 16:26:08 EDT</pubDate>
</item>

<item>
<title>Re: Security researchers warn of new &#x27;clickjacking&#x27; browser bugs</title>
<link>http://www.dslreports.com/forum/remark,21235562</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Interesting.  Thanks.<br><br>For some time, now, I have been using multiple firefox profiles.  Banking, router configuration, etc, uses one profile.  Ordinary browsing uses another.  This separation should greatly reduce the risk from all kinds of cross site vulnerabilities.<br><br>So, sure, a clever cross site attack might change my dslr profile, but it could not change my router configuration nor could it do something with my bank account.<br><small>--<br>AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.3</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21235562</guid>
<pubDate>Wed, 08 Oct 2008 15:32:47 EDT</pubDate>
</item>

<item>
<title>Re: Security researchers warn of new &#x27;clickjacking&#x27; browser bugs</title>
<link>http://www.dslreports.com/forum/remark,21234959</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : Firefox users can avail themselves of NoScript: &raquo;<A HREF="/forum/r21229158-NoScript-Fights-Clickjacking">NoScript Fights Clickjacking</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21234959</guid>
<pubDate>Wed, 08 Oct 2008 13:41:51 EDT</pubDate>
</item>

<item>
<title>Re: Security researchers warn of new &#x27;clickjacking&#x27; browser bugs</title>
<link>http://www.dslreports.com/forum/remark,21234369</link>
<description><![CDATA[<A HREF="/useremail/u/1376598"><b>swhx7</b></A> : Details are public now. &raquo;<A HREF="http://ha.ckers.org/blog/20081007/clickjacking-details/" >ha.ckers.org/blog/20081007/click&middot;&middot;&middot;details/</A><br><br>More: &raquo;<A HREF="http://securosis.com/2008/10/07/clickjacking-details-analysis-and-advice/" >securosis.com/2008/10/07/clickja&middot;&middot;&middot;-advice/</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21234369</guid>
<pubDate>Wed, 08 Oct 2008 11:57:57 EDT</pubDate>
</item>

<item>
<title>Re: Security researchers warn of new &#x27;clickjacking&#x27; browser bugs</title>
<link>http://www.dslreports.com/forum/remark,21196355</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : Just as i thought this is nothing........ (Only people that dont know what they are doing might be affected)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21196355</guid>
<pubDate>Wed, 01 Oct 2008 00:55:50 EDT</pubDate>
</item>

<item>
<title>Re: Security researchers warn of new &#x27;clickjacking&#x27; browser bugs</title>
<link>http://www.dslreports.com/forum/remark,21194914</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : n/m]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21194914</guid>
<pubDate>Tue, 30 Sep 2008 20:25:51 EDT</pubDate>
</item>

<item>
<title>Re: Security researchers warn of new &#x27;clickjacking&#x27; browser bugs</title>
<link>http://www.dslreports.com/forum/remark,21194525</link>
<description><![CDATA[<A HREF="/useremail/u/1056836"><b>ravencajun</b></A> : Oleg, glad that you've started a dedicated thread for this.<br><br>times 2!<br>I was going to start one a few days ago then found the other threads mentioned.<br>These were some of the other articles recently, might as well put them all in one spot.<br><A HREF="http://blogs.zdnet.com/security/?p=1972">Clickjacking: Researchers raise alert for scary new cross-browser exploit</a><br><A HREF="http://blogs.zdnet.com/security/?p=1973">Firefox + NoScript vs Clickjacking</a><br><A HREF="http://blogs.zdnet.com/security/?p=1733">Adobe Flash ads launching clipboard hijack attack</a><br><A HREF="http://ubuntu-virginia.ubuntuforums.org/showthread.php?t=886905">copy and paste</a>  from the ubuntu forums.<br><br>It is definitely a topic that needs attention.<br>Some of the scenarios that have been mentioned are pretty scary.<br>Hopefully something constructive will come out of the discussions and a fix is on the horizon.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21194525</guid>
<pubDate>Tue, 30 Sep 2008 19:14:17 EDT</pubDate>
</item>

<item>
<title>Re: Security researchers warn of new &#x27;clickjacking&#x27; browser bugs</title>
<link>http://www.dslreports.com/forum/remark,21191866</link>
<description><![CDATA[<A HREF="/useremail/u/878241"><b>JohnInSJ</b></A> : <div class="bquote"><small>said by  redwolfe_98 <A HREF="/useremail/u/408621"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>i don't see how this "click-jacking" issue could be much of a problem..<br> </div>I guess it depends on if you hang out at compromised sites, while having important authenticated content open in another window at the same time, while madly clicking on everything you can (or maybe cannot) see.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21191866</guid>
<pubDate>Tue, 30 Sep 2008 11:45:44 EDT</pubDate>
</item>

<item>
<title>Re: Security researchers warn of new &#x27;clickjacking&#x27; browser bugs</title>
<link>http://www.dslreports.com/forum/remark,21180501</link>
<description><![CDATA[<A HREF="/useremail/u/408621"><b>redwolfe_98</b></A> : i don't see how this "click-jacking" issue could be much of a problem..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21180501</guid>
<pubDate>Sun, 28 Sep 2008 00:29:03 EDT</pubDate>
</item>

<item>
<title>Re: Security researchers warn of new &#x27;clickjacking&#x27; browser bugs</title>
<link>http://www.dslreports.com/forum/remark,21175142</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : This is an <i>extremely serious</i> and difficult vulnerability.<br><br><i>Doctor Four</i> and I posted important information about this in a different thread: &raquo;<A HREF="/forum/remark,21170142">Re: Malvertisement on MSNBC.com using clipboard (copy/paste)</A> . Please read it.<br><br>Giorgio Maone, the creator of NoScript, "had access to detailed information about how this attack works". He said "I was told that it's indeed "very, freaking scary" and "near impossible" to fix properly."<br><br><i>swhx7</i> added this:<br><div class="bquote"><small>said by  swhx7 <A HREF="/useremail/u/1376598"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>The discoverers have been vague about just what the "clickjacking" involves. The reason of course is the same as in the recent Kaminsky/DNS thing, to give vendors time to patch. This has led to some anxiety about how site maintainers and surfers can be safe.<br><br>In looking around however, I found a clear explanation of at least one implementation of it: &raquo;<A HREF="http://lists.whatwg.org/pipermail/whatwg-whatwg.org/2008-September/016284.html" >lists.whatwg.org/pipermail/whatw&middot;&middot;&middot;284.html</A><br><br>The above is already out there, so I'm not making it any worse by linking.<br><br>I favor Zalewski's #4, because it puts the user most in control.</div>Oleg, glad that you've started a dedicated thread for this.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21175142</guid>
<pubDate>Fri, 26 Sep 2008 19:51:40 EDT</pubDate>
</item>

<item>
<title>Security researchers warn of new &#x27;clickjacking&#x27; browser bugs</title>
<link>http://www.dslreports.com/forum/remark,21175031</link>
<description><![CDATA[<A HREF="/useremail/u/910278"><b>Oleg</b></A> : September 26, 2008 (Computerworld) Security researchers warned today that a new class of vulnerabilities dubbed "clickjacking" puts users of every major browser at risk from attack.<br><br>Read more &raquo;<A HREF="http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9115700&source=NLT_PM&nlid=8" >www.computerworld.com/action/art&middot;&middot;&middot;M&nlid=8</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21175031</guid>
<pubDate>Fri, 26 Sep 2008 19:28:27 EDT</pubDate>
</item>

</channel>
</rss>
