Announcement

Collapse
No announcement yet.

Good News: Clickjacking

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Good News: Clickjacking

    By good news, I actually of course mean very bad news. Researchers are raising alert of a new browser exploit that's being touted as "very, freaking scary." This article was posted earlier today on ZDNet.com. Worth a read as it affects almost all major browsers being used.

    Clickjacking: Researchers raise alert for scary new cross-browser exploit

    Later, ZDNet.com posted an update with an email from NoScript creator, Giorgio Maone, who had this to say:

    Hi Ryan, I’ve seen a lot of speculation and confusion in the comments to your Clickjacking article about NoScript not being able to mitigate [the issue].
    I had access to detailed information about how this attack works and I can tell you the following:
    1. It’s really scary
    2. NoScript in its default configuration can defeat most of the possible attack scenarios (i.e. the most practical, effective and dangerous) — see this comment by Jeremiah Grossman himself.
    3. For 100% protection by NoScript, you need to check the “Plugins|Forbid <IFRAME>” option.
    Cheers,
    Giorgio
    Firefox + NoScript vs Clickjacking


    So essentially, while it will affect any default installation of FF, using NoScript (like you should be anyway) seems to block the issue anyway. Those using not firefox, good luck I guess.
    ______________________________
    Wow. Apparently no one really cares about this shit other than me.

    Confused.
    Last edited by Ameroth; 09-26-2008, 06:57 PM. Reason: Automerged Doublepost




    PLD75 DRK60 lots of other levels.
    ------
    Shackle their minds when they're bent on the cross
    When ignorance reigns, life is lost



  • #2
    Re: Good News: Clickjacking

    Lawl. I care, just knew about it already ^^
    signatures are for pussies mew mew mew, here's mine

    Comment


    • #3
      Re: Good News: Clickjacking

      {I don't understand.}

      Since there's really no information in the first link (it doesn't say "this is what this does, here's how it effects you")...

      Ok, I got that an attacker could cause you to click somewhere else. But... to what end? To redirect you to pages that install some spyware that you have blocked/won't be installed anyway because you've taken other preventative steps? Instead of going to eBay I'd get sent to ebayspoof.hackersite? If I noticed things like that, and if they happened consistently, generally I would kill the browser process and restart it with a new session. That would clear it up just as well...

      I don't know. I'm just having a hard time finding the relevance on how this would effect me.
      Kindadarii (Bahamut)
      90PUP / 90SMN / 90BRD / 90WHM / 59DNC
      70.3 + 2 Woodworking
      52.2 Synergy


      Breeding Chocobos? Visit Chocobreeder.com to find chocobos in your area!

      Comment


      • #4
        Re: Good News: Clickjacking

        Firefox just recently release version 3.0.3, is it because of this issue? Or it has nothing to do with that?
        Server: Quetzalcoatl
        Race: Hume Rank 7
        75 PLD, 75 SAM, 75 WAR, 75 NIN, 75 MNK, 65 BLU

        Comment

        Working...
        X