Free Scan: Update Your PC's Outdated Drivers to Optimize Performance
September 26th, 2008, 09:52 PM
|
#1 (permalink)
| | Sea-Ninja wannabe
Join Date: Apr 2002 Location: Albany, Ga.
Posts: 8,240
| WARNING on clickjacking. Clickjacking affects almost every browser including Apple Safari, Google Chrome, Microsoft Internet Explorer(ALL versions), Mozilla Firefox, and Opera. Quote:
A mysterious cross-platform Web browser exploit technique called "Clickjacking" has led to a call to disable all browser scripting and plug-ins until the vulnerability can be addressed.
U.S. CERT on Friday issued a warning about the technique. Citing a September 15 blog post by Jeremiah Grossman, founder and CTO of WhiteHat Security, U.S. CERT said, "Clickjacking gives an attacker the ability to trick a user into clicking on something only barely or momentarily noticeable. Therefore, if a user clicks on a Web page, they may actually be clicking on content from another page."
| Quote:
The government security agency also said the flaw affects most Web browsers and that no fix is available, but that risks can be mitigated by disabling scripting and plug-ins in one's browser.
For Firefox users, the NoScript Firefox extension can do that. Grossman in a blog comment posting also suggests the use of security-related plug-ins like FlashBlock, Adblock Plus, and CustomizeGoogle. (Presumably, these plug-ins should not be disabled.)
Clickjacking affects Apple Safari, Google Chrome, Microsoft Internet Explorer, Mozilla Firefox, and Opera.
| Be careful out there.
__________________
They say technology slows down for no one. I know it outruns my wallet. I figure its because my wallet isn't light enough yet.
|
| |
September 26th, 2008, 10:32 PM
|
#2 (permalink)
| | SoMuchAnime-SoLittleTime
Join Date: Aug 2003 Location: Plymouth, WI
Posts: 13,697
|
I don't think clickjacking is any more dangerous than some even simpler attacks. If somebody is able to put raw HTML/Javascript onto a page they can do many other attacks. Even without being able to insert HTML/Javascript one can do similar attacks if someone is able to link to an image through BBCode or avatars for example. Cross-site request forgery - Wikipedia, the free encyclopedia
Heck, I can run a CSRF on any user through this forum if I wanted to, it is a very simple attack to do.
__________________
The mark of the immature man is that he wants to die nobly for a cause, while the mark of a mature man is that he wants to live humbly for one.
|
| |
September 27th, 2008, 06:16 AM
|
#3 (permalink)
| | Sea-Ninja wannabe
Join Date: Apr 2002 Location: Albany, Ga.
Posts: 8,240
|
Yes, the exploit is based onits an old concept, BUT this exploit is different in that it affects virtually every browser(only text based browsers are immune) including at least one Adobe product. To stop it we must disable scripting and plug-ins in our browsers.
The fact that personal information can be stolen in this way makes this a particularly nasty exploit IMO. |
| |
September 27th, 2008, 11:04 AM
|
#4 (permalink)
| | SoMuchAnime-SoLittleTime
Join Date: Aug 2003 Location: Plymouth, WI
Posts: 13,697
|
The same thing can be done with any image links, which will affect anything that automatically loads images in the <img> tag. |
| |
October 1st, 2008, 05:01 AM
|
#5 (permalink)
| | Member
Join Date: Feb 2008
Posts: 416
|
This is a frame trick and MOST OF US arent dumb enough to think we are on another site then the one listed in the address bar!!! (And if we are unsure,we just paste links directly in the bar (But alot of people dont know the first thing about this kinda stuff which makes this very dangerous))
More info > http://www.wilderssecurity.com/showthread.php?t=221353 |
| |
October 1st, 2008, 04:23 PM
|
#6 (permalink)
| | SoMuchAnime-SoLittleTime
Join Date: Aug 2003 Location: Plymouth, WI
Posts: 13,697
|
No, it isn't a frame trick.
I could be running a similar attack against you now automatically just by your browser loading my avatar. |
| |
October 2nd, 2008, 12:35 AM
|
#7 (permalink)
| | Member
Join Date: Feb 2008
Posts: 416
| |
| |
October 2nd, 2008, 06:08 PM
|
#8 (permalink)
| | Member
Join Date: Apr 2008 Location: Norway MI
Posts: 127
|
now remember kids, always where protection when surfing the web (thats why i have avast) and yes ive seen this before 
and im not really concerned about my informatio being stolen, i lie to every sight i register, i use a different computer protected by kasperskys to do my shopping
__________________
GLaDOS: (going to be built on jan. 2nd)
P5Q3 asus mobo, 4 gb ddr3 ram, hd 4870x2, 22" samsung monitor, q6600, vista ultimate 64 bit
Last edited by TimeDeatH : October 2nd, 2008 at 06:10 PM.
|
| |
October 2nd, 2008, 06:16 PM
|
#9 (permalink)
| | Super Stealthy Moderator
Join Date: Jan 2003 Location: Outside the box
Posts: 4,330
| Quote:
Originally Posted by TimeDeatH now remember kids, always where protection when surfing the web (thats why i have avast) and yes ive seen this before 
and im not really concerned about my informatio being stolen, i lie to every sight i register, i use a different computer protected by kasperskys to do my shopping | Neither of which would do anything to protect you against the exploit in question. 
__________________ “Every question involves someone having to work for an answer, isn't it about time you did your share”
"The true measure of a man is the degree to which he has managed to subjugate his ego." |
| |
October 3rd, 2008, 10:56 AM
|
#10 (permalink)
| | Member
Join Date: Apr 2008 Location: Norway MI
Posts: 127
| Quote:
Originally Posted by RicheemxX Neither of which would do anything to protect you against the exploit in question.  | then i got random attacks from surfing the web...ill try to get an image next time it happens |
| | |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | | |
Posting Rules
| You may post new threads You may post replies You may not post attachments You may not edit your posts HTML code is Off | | |
Similar Threads | | Thread | Thread Starter | Forum | Replies | Last Post | | WARNING!! | Droppyale | IMO Community | 25 | October 2nd, 2008 07:40 PM | | Warning | project vegas | General Tech Discussion | 3 | October 17th, 2005 10:41 PM | | Warning.. | Cruez | IMO Community | 16 | May 1st, 2002 02:16 AM | | Warning, warning labels inside..... | angelcat | IMO Community | 40 | April 18th, 2002 01:00 AM | | Most Active Discussions | | | | | Recent Discussions  | | | | | |