home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Join TechIMO for Free!
Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read
Reply Get bargains at  »  Dealighted.com
 
Thread Tools
Currently Active Users: 1969
Discussions: 186,591, Posts: 2,226,905, Members: 230,218
Free Scan: Update Your PC's Outdated Drivers to Optimize Performance
Old September 26th, 2008, 09:52 PM   Digg it!   #1 (permalink)
Sea-Ninja wannabe
 
no1_vern's Avatar
 
Join Date: Apr 2002
Location: Albany, Ga.
Posts: 8,240
Exclamation
WARNING on clickjacking.

Clickjacking affects almost every browser including Apple Safari, Google Chrome, Microsoft Internet Explorer(ALL versions), Mozilla Firefox, and Opera.

Quote:
A mysterious cross-platform Web browser exploit technique called "Clickjacking" has led to a call to disable all browser scripting and plug-ins until the vulnerability can be addressed.
U.S. CERT on Friday issued a warning about the technique. Citing a September 15 blog post by Jeremiah Grossman, founder and CTO of WhiteHat Security, U.S. CERT said, "Clickjacking gives an attacker the ability to trick a user into clicking on something only barely or momentarily noticeable. Therefore, if a user clicks on a Web page, they may actually be clicking on content from another page."

Quote:
The government security agency also said the flaw affects most Web browsers and that no fix is available, but that risks can be mitigated by disabling scripting and plug-ins in one's browser.
For Firefox users, the NoScript Firefox extension can do that. Grossman in a blog comment posting also suggests the use of security-related plug-ins like FlashBlock, Adblock Plus, and CustomizeGoogle. (Presumably, these plug-ins should not be disabled.)

Clickjacking affects Apple Safari, Google Chrome, Microsoft Internet Explorer, Mozilla Firefox, and Opera.
Be careful out there.
__________________
They say technology slows down for no one. I know it outruns my wallet. I figure its because my wallet isn't light enough yet.

no1_vern is offline   Reply With Quote
TechIMO.com Ads - Login or register for less ads.
How many errors does your computer have?

You no longer need to guess! This free stability scan and registry cleaner download will give you a complete diagnosis of your Windows registry, identifying errors and conflicts.

FREE instant scan


Guest, Register Free! to remove this ad and get your tech support questions answered in minutes!
Old September 26th, 2008, 10:32 PM     #2 (permalink)
SoMuchAnime-SoLittleTime
 
EXreaction's Avatar
 
Join Date: Aug 2003
Location: Plymouth, WI
Posts: 13,697
Blog Entries: 1
Send a message via ICQ to EXreaction Send a message via AIM to EXreaction Send a message via MSN to EXreaction Send a message via Yahoo to EXreaction
I don't think clickjacking is any more dangerous than some even simpler attacks. If somebody is able to put raw HTML/Javascript onto a page they can do many other attacks. Even without being able to insert HTML/Javascript one can do similar attacks if someone is able to link to an image through BBCode or avatars for example.

Cross-site request forgery - Wikipedia, the free encyclopedia

Heck, I can run a CSRF on any user through this forum if I wanted to, it is a very simple attack to do.
__________________
The mark of the immature man is that he wants to die nobly for a cause, while the mark of a mature man is that he wants to live humbly for one.

EXreaction is online now   Reply With Quote
Old September 27th, 2008, 06:16 AM     #3 (permalink)
Sea-Ninja wannabe
 
no1_vern's Avatar
 
Join Date: Apr 2002
Location: Albany, Ga.
Posts: 8,240
Yes, the exploit is based onits an old concept, BUT this exploit is different in that it affects virtually every browser(only text based browsers are immune) including at least one Adobe product. To stop it we must disable scripting and plug-ins in our browsers.

The fact that personal information can be stolen in this way makes this a particularly nasty exploit IMO.

no1_vern is offline   Reply With Quote
Old September 27th, 2008, 11:04 AM     #4 (permalink)
SoMuchAnime-SoLittleTime
 
EXreaction's Avatar
 
Join Date: Aug 2003
Location: Plymouth, WI
Posts: 13,697
Blog Entries: 1
Send a message via ICQ to EXreaction Send a message via AIM to EXreaction Send a message via MSN to EXreaction Send a message via Yahoo to EXreaction
The same thing can be done with any image links, which will affect anything that automatically loads images in the <img> tag.
EXreaction is online now   Reply With Quote
Old October 1st, 2008, 05:01 AM     #5 (permalink)
Member
 
Join Date: Feb 2008
Posts: 416
This is a frame trick and MOST OF US arent dumb enough to think we are on another site then the one listed in the address bar!!! (And if we are unsure,we just paste links directly in the bar (But alot of people dont know the first thing about this kinda stuff which makes this very dangerous))

More info > http://www.wilderssecurity.com/showthread.php?t=221353
Dude111 is offline   Reply With Quote
Old October 1st, 2008, 04:23 PM     #6 (permalink)
SoMuchAnime-SoLittleTime
 
EXreaction's Avatar
 
Join Date: Aug 2003
Location: Plymouth, WI
Posts: 13,697
Blog Entries: 1
Send a message via ICQ to EXreaction Send a message via AIM to EXreaction Send a message via MSN to EXreaction Send a message via Yahoo to EXreaction
No, it isn't a frame trick.

I could be running a similar attack against you now automatically just by your browser loading my avatar.
EXreaction is online now   Reply With Quote
Old October 2nd, 2008, 12:35 AM     #7 (permalink)
Member
 
Join Date: Feb 2008
Posts: 416
Hmmmmmmm
Dude111 is offline   Reply With Quote
Old October 2nd, 2008, 06:08 PM     #8 (permalink)
Member
 
TimeDeatH's Avatar
 
Join Date: Apr 2008
Location: Norway MI
Posts: 127
Send a message via MSN to TimeDeatH
now remember kids, always where protection when surfing the web (thats why i have avast) and yes ive seen this before
and im not really concerned about my informatio being stolen, i lie to every sight i register, i use a different computer protected by kasperskys to do my shopping
__________________
GLaDOS: (going to be built on jan. 2nd)
P5Q3 asus mobo, 4 gb ddr3 ram, hd 4870x2, 22" samsung monitor, q6600, vista ultimate 64 bit

Last edited by TimeDeatH : October 2nd, 2008 at 06:10 PM.
TimeDeatH is offline   Reply With Quote
Old October 2nd, 2008, 06:16 PM     #9 (permalink)
Super Stealthy Moderator
 
RicheemxX's Avatar
 
Join Date: Jan 2003
Location: Outside the box
Posts: 4,330
Blog Entries: 4
Send a message via Yahoo to RicheemxX
Quote:
Originally Posted by TimeDeatH View Post
now remember kids, always where protection when surfing the web (thats why i have avast) and yes ive seen this before
and im not really concerned about my informatio being stolen, i lie to every sight i register, i use a different computer protected by kasperskys to do my shopping
Neither of which would do anything to protect you against the exploit in question.
__________________
“Every question involves someone having to work for an answer, isn't it about time you did your share”
"The true measure of a man is the degree to which he has managed to subjugate his ego."
RicheemxX is offline   Reply With Quote
Old October 3rd, 2008, 10:56 AM     #10 (permalink)
Member
 
TimeDeatH's Avatar
 
Join Date: Apr 2008
Location: Norway MI
Posts: 127
Send a message via MSN to TimeDeatH
Quote:
Originally Posted by RicheemxX View Post
Neither of which would do anything to protect you against the exploit in question.
then i got random attacks from surfing the web...ill try to get an image next time it happens
TimeDeatH is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
WARNING!! Droppyale IMO Community 25 October 2nd, 2008 07:40 PM
Warning project vegas General Tech Discussion 3 October 17th, 2005 10:41 PM
Warning.. Cruez IMO Community 16 May 1st, 2002 02:16 AM
Warning, warning labels inside..... angelcat IMO Community 40 April 18th, 2002 01:00 AM

Most Active Discussions
Is It Just Me? (495)
heatsink issue (8)
Word Association!! (1655)
SSD's, RAID, and External Backup (6)
New Mobo (16)
1 internet. 1 house. 3 computer. ho.. (11)
UPGRADING C/D DRIVE TO 250GB & .. (10)
Is This A Compatible Gaming PC? (16)
Connected to LAN but unable to use .. (5)
Recent Discussions
Which applications are the best.. (3)
1 internet. 1 house. 3 computer.. (12)
Hard Core Overclock (10)
C++ compiler suggestions (2)
Letter Count Array (3)
SSD's, RAID, and External Backu.. (6)
Folderchat: The Holiday thread (113)
heatsink issue (8)
FS: New Benny Hill Megaset DVD .. (6)
Computer won't start (2)
FS: Dell 6000 laptop, modded 36.. (2)
Apple iPod touch 16 GB $200 (4)


All times are GMT -4. The time now is 01:19 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28