
how-to block ads
|
  Doctor Four My other vehicle is a TARDIS Premium join:2000-09-05 Dallas, TX
·AT&T U-Verse
| reply to Doctor Four Re: Malvertisement on MSNBC.com using clipboard (copy/paste)
Adobe says they are going to fix this, but there is now a much more serious threat involving clickjacking:
»blogs.zdnet.com/security/?p=1972
quote: In a nutshell, its when you visit a malicious website and the attacker is able to take control of the links that your browser visits. The problem affects all of the different browsers except something like lynx. The issue has nothing to do with JavaScript so turning JavaScript off in your browser will not help you. Its a fundamental flaw with the way your browser works and cannot be fixed with a simple patch. With this exploit, once youre on the malicious web page, the bad guy can make you click on any link, any button, or anything on the page without you even seeing it happening.
Firefox and NoScript can give a degree of protection against this, according to an email the creator, Giorgio Maone, sent the ZDNet blogger.
»blogs.zdnet.com/security/?p=1973 -- "The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)
| |  SUMware Premium join:2002-05-21
2 edits | DF, thanks for posting this additional information.
From your link »blogs.zdnet.com/security/?p=1973 it's worth excerpting the following: quote: In response to my story earlier on the cross-browser Clickjacking exploit/threat, I received the following e-mail from Giorgio Maone, creator of the popular Firefox NoScript plug-in:
Hi Ryan,
Ive seen a lot of speculation and confusion in the comments to your Clickjacking article about NoScript not being able to mitigate [the issue].
I had access to detailed information about how this attack works and I can tell you the following:
1. Its really scary 2. NoScript in its default configuration can defeat most of the possible attack scenarios (i.e. the most practical, effective and dangerous) see this comment by Jeremiah Grossman himself. 3. For 100% protection by NoScript, you need to check the "Plugins|Forbid [IFRAME]" option.. Cheers, Giorgio I also received private confirmation from a high-level source at an affected vendor about the true severity of this issue. In a nutshell, I was told that its indeed very, freaking scary and near impossible to fix properly.
Tod Beardsley from BreakingPoint has posted a few proof-of-concept exploits with speculation around clickjacking.
| |
-
|