• Main
  • Apple
  • Gamers
  • Software
  • Galleries



Lost Password? | Register
NewXwin.net
New clickjacking affects all browsers; cause remains unknown
Shakil Shakil published 26 Sep 2008, 20:29 in main - 442 views
Fav
ImageJeremiah Grossman and Robert "Rsnake" Hansen initially planned to reveal details on a new browser-agnostic clickjacking exploit at the Open Web Application Security Project (OWASP) in New York City this week, but voluntarily pulled the presentation after discovering that the 0-day flaw affected an Adobe product. The term "clickjacking" refers to a process by which a user is forced to click on a link without his or her knowledge—the link itself may be nearly invisible or visible for only a fraction of a second.

Clickjacking isn't a new attack vector, but according to Grossman and Hansen, it's one that is "severely underappreciated and largely undefended." What makes the attack noteworthy, in this case, is that it appears to be completely browser-agnostic, and affects both Firefox 2 and 3, all versions of IE (including 8), and presumably all versions of Opera, Konquerer, Safari, and whatever other extremely marginalized and/or FailCat type of browser one might use to surf the web. The only browsers currently immune to whatever it is the two men discovered are text-based products, such as Lynx.

In this case, "whatever it is," actually is the only appropriate label for this new attack method; Grossman and Hansen have released virtually no information on how one would actually exploit the vulnerability. Grossman and his teammate appear to have held off publishing after Adobe requested they do so, rather than as a favor to the browser market. In his blog, Grossman writes: "At the time, we believed our discoveries were more in line with generic Web browsers behavior, not traditional “exploits,” and that guarding against clickjacking was largely the browser vendors' responsibility."

Grossman and Hansen have, however, released a bit of information on what won't protect a user from the exploit. Turning Javascript off is apparently useless—the attack doesn't use it. Instead, it takes advantage of what the two call a "fundamental flaw" inherent to all modern browsers, and an issue that cannot be fixed with a quick patch. Using a frame buster script will protect a person from assaults that utilize cross-domain scripting, but will not prevent the attack from operating normally if it's on a page the user is visiting.

As exploits go, this particular one seems a tempest in a teapot. The vulnerability in question may affect all web browsers, but the total dearth of publicly available data means anyone wanting to utilize it has their work cut out for them. Grossman states that this particular attack is capable of some "pretty spooky," things, but that's all the detail we get. I'm not a fan of security through obscurity, but that's not what anyone is advocating—Adobe has acknowledged the problem, and the dev teams on both Firefox and IE are undoubtedly aware of the flaw's existence. Hopefully they also received a bit more information than the public did.

Copyright © 2008 Ars Technica, LLC
Tags: Clickjacking, Browsers, OWASP, Adobe, Javascript
    • 1
    • 2
    • 3
    • 4
    • 5
    4.00 (1 Vote)
    popup tail
  • Digg this
Prev Article: Nokia to unveil touchscreen phone next week Next Article: It's Official: Windows 7 at PDC, WinHEC
  • Web 2.0: Google Chrome To Support Add-Ons
  • How to Preview New Google Chrome Features
  • Non-political: more on Google Chrome
  • Show More Related Articles
  • 0 Comments
  • 1 Favs

Who Faved This?

  • ShaonShaon 
Random Technology News
Fav
Apple Safari 3.1.2
Morshad by Morshad in Software News - 06/26/08 · 1 favs
Fav
CrossOver - Windows Apps on Macs - without Windows
Morshad by Morshad in Technology News - 07/31/06 · 0 favs
Fav
Firefox, IE vulnerable to fake login pages?
Morshad by Morshad in Technology News - 11/23/06 · 0 favs
Fav
Vista Media Packaging Shots & NY Launch Summary
Shaon by Shaon in Technology News - 01/30/07 · 0 favs
Fav
Wii Development Becomes AiLive
Shaon by Shaon in Gamers News - 10/13/06 · 0 favs
Latest Technology News
Fav
CES 2009 Sobers Up for Recession
Shakil by Shakil in Technology News - 6 hours ago · 1 favs
Fav
Windows 7 Beta Gets Official
Morshad by Morshad in Technology News - 7 hours ago · 1 favs
Fav
Asus debuts S121 netbook with Windows 7 and 512GB SSD
Shaon by Shaon in Technology News - 22 hours ago · 1 favs
Fav
Verizon picks Microsoft search over Google and Yahoo
Morshad by Morshad in Technology News - 22 hours ago · 1 favs
Fav
Future of Macworld Expo up in the air
Shakil by Shakil in Apple News - 22 hours ago · 0 favs
Popular Technology News
Fav
Auslogics Disk Defrag with Command Line
Asphodel Blanche by Asphodel Blanche in Software News - 01/07/09 · 1 favs
Fav
Asus debuts S121 netbook with Windows 7 and 512GB SSD
Shaon by Shaon in Technology News - 22 hours ago · 1 favs
Fav
Future of Macworld Expo up in the air
Shakil by Shakil in Apple News - 22 hours ago · 0 favs
Fav
OpenOffice.org 3.0.1 RC1
Shaon by Shaon in Software News - 22 hours ago · 1 favs
Fav
Verizon picks Microsoft search over Google and Yahoo
Morshad by Morshad in Technology News - 22 hours ago · 1 favs

Main Menu

News
Advanced Search
Subscribe to Newsletter

Advertisement

Subscribe to NewXwin.net

Add to Technorati Favorites

Join My Community at MyBloglog!

My BlogCatalog BlogRank

TwitterCounter for @Morshad



Featured Sites

Privacy Statement | Contact Us
Copyright © 2003 - 2008 NS Network Organization. All right reserved.
NSOrg.com | EZthemes | Projects | Technology News | Apple News | Gamers News | Software News | Softwares & Products Reviews | Photoshop Tutorials