Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Malvertisement on MSNBC.com using clipboard (copy/paste)
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Security Software Updates - 26 Sep 2008 »
« Firefox 3.0.2 Released  
AuthorAll Replies


Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
·AT&T U-Verse

reply to Doctor Four
Re: Malvertisement on MSNBC.com using clipboard (copy/paste)

Adobe says they are going to fix this, but there is now a much more serious threat involving clickjacking:

»blogs.zdnet.com/security/?p=1972

quote:
In a nutshell, it’s when you visit a malicious website and the attacker is able to take control of the links that your browser visits. The problem affects all of the different browsers except something like lynx. The issue has nothing to do with JavaScript so turning JavaScript off in your browser will not help you. It’s a fundamental flaw with the way your browser works and cannot be fixed with a simple patch. With this exploit, once you’re on the malicious web page, the bad guy can make you click on any link, any button, or anything on the page without you even seeing it happening.

Firefox and NoScript can give a degree of protection against this, according to an email the creator, Giorgio Maone, sent the ZDNet blogger.

»blogs.zdnet.com/security/?p=1973
--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)

SUMware
Premium
join:2002-05-21


2 edits
DF, thanks for posting this additional information.

From your link »blogs.zdnet.com/security/?p=1973 it's worth excerpting the following:
quote:
In response to my story earlier on the cross-browser Clickjacking exploit/threat, I received the following e-mail from Giorgio Maone, creator of the popular Firefox NoScript plug-in:
Hi Ryan,

I’ve seen a lot of speculation and confusion in the comments to your Clickjacking article about NoScript not being able to mitigate [the issue].

I had access to detailed information about how this attack works and I can tell you the following:
1. It’s really scary
2. NoScript in its default configuration can defeat most of the possible attack scenarios (i.e. the most practical, effective and dangerous) — see this comment by Jeremiah Grossman himself.
3. For 100% protection by NoScript, you need to check the "Plugins|Forbid [IFRAME]" option..
Cheers,
Giorgio
I also received private confirmation from a high-level source at an affected vendor about the true severity of this issue. In a nutshell, I was told that it’s indeed “very, freaking scary” and “near impossible” to fix properly.

Tod Beardsley from BreakingPoint has posted a few proof-of-concept exploits with speculation around clickjacking.
-
Forums » Up and Running » Security » SecuritySecurity Software Updates - 26 Sep 2008 »
« Firefox 3.0.2 Released  


Friday, 04-Dec 04:34:33 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [162] Comcast Releasing Promised Usage Meter
· [141] Avast Antivirus Has Gone Mad
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [102] Comcast Makes NBC Universal Acquisition Official
· [85] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [70] Baltimore To Ban Lazy Cable Installs
· [65] Sprint Defuses GPS Privacy Media Bomb
· [64] Broadband Killed The Game Console
· [59] FCC Ponders Moving From PSTN To IP Voice
Most people now reading
· False positive in Avast! or is it real? [Security]
· [Equipment] Ubiquiti third party firmware for the M series Bulle [Wireless Service Providers]
· [Rant] Disrespect of PTO [Rants, Raves, and Praise]
· Windows 7 boot manager editing questions [Microsoft Help]
· [ Classes] 3.2.2 Rogue [World of Warcraft]
· Using AirMax to provide triple play services? [Wireless Service Providers]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· [Business] how to bridge a smc 8014 business class modem [Comcast HSI]
· [WIN7] Outlook express under Windows 7? [Microsoft Help]
· Warrior tank seem underpowered these days [World of Warcraft]