myITforum.com Community Forum myITforum.com Community Forum

Home  Forums  Blogs  Live Support chat  Search Articles  Wiki  FAQ  Email Lists  Register  Login  My Profile  Inbox  Address Book  My Subscription  My Forums 

Photo Gallery  Member List  Search  Calendars  FAQ  Ticket List  Log Out

All Forums RSS Feed Subscription:


  


Clickjacking - What is it?

 
View related threads: (in this forum | in all forums)

Logged in as: Guest
  Printable Version
All Forums >> [Security, AntiVirus, and Patching] >> Breaking Virus & Security News >> Clickjacking - What is it? Page: [1]
Login
Message << Older Topic   Newer Topic >>
Clickjacking - What is it? - 10/20/2008 11:10:18 AM  1 votes
hwaldron


Posts: 3597
Score: 264
Joined: 9/12/2002
From: Roanoke VA, USA
Status: offline
While clickjacking is not a new concept, it's gaining popularity as technique used for malicious websites.  As iFrames are logical divisions of a webpage, the approach is to create a "transparent iFrame page" that lines up exactly with the real web page being accessed. The buttons in the "invisible iFrame page" replace the buttons in the real web page.  When the user clicks on the button, they may allow malicious software to be loaded or security at the true site they were trying to access to become compromised.

The Adobe Flash facility is one of the most widely installed software products in the world, as it's used by all major browsers.  Adobe Flash (v9 and lower) is vulnerable to these attacks and it's a popular method now being used to achieve clickjacking.  To stay protected from this threat, users should move to Adobe Flash v10, keeping AV protection updated, keep all O/S and browsers updated, and avoid risky websites.   

Clickjacking - What is it?
http://www.avertlabs.com/research/blog/index.php/2008/10/15/clickjacking/
http://en.wikipedia.org/wiki/Clickjacking
http://www.mxlogic.com/itsecurityblog/1/2008/10/What-is-ClickJacking.cfm
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9115818
http://blogs.zdnet.com/security/?p=1972
http://www.securityfocus.com/news/11534?ref=rss
http://www.schneier.com/blog/archives/2008/10/clickjacking.html

QUOTE: Let’s use an example. You have a web page A controlled by an attacker. A contains an IFRAME element B. In a clickjack attack, B would be set to transparent and the z-index property of the layer set to higher than other elements of page A via CSS. B will also need to be so big so that the user can click it’s content. The attacker can then place any button to do anything he wants in B. Then the attacker can place some buttons on page A. The location of the buttons in B must match the buttons in A. So when the user clicks on a button on page A, they are actually clicking the button in B because the z-index property of B’s buttons are higher than A’s buttons. This attack uses DHTML, does not require Javascript, so disabling Javascript will not help.

This vulnerability affects multiple web browsers. Unfortunately, no patch for it is currently available, so users should be careful. The vulnerability has also been found to affect Adobe Flash Player, the most popular rich media internet application today. Adobe has released a security advisory and provided a workaround.

Clickjacking - Adobe recommended workarounds (move to version 10)
http://msmvps.com/blogs/harrywaldron/archive/2008/10/16/adobe-flash-version-10-security-release-fixes-many-bugs.aspx
http://www.adobe.com/support/security/advisories/apsa08-08.html
http://www.adobe.com/support/security/bulletins/apsb08-18.html

_____________________________


Harry Waldron - Security News & Best Practices Blog
Post #: 1
RE: Clickjacking - What is it? - 10/21/2008 2:26:16 PM   
awenlock


Posts: 357
Score: 188
Joined: 3/8/2005
Status: offline
Great post Harry 

This is certainly Topic of the month at the moment since Adobe released an update to Flash Player and is something users need to be aware of as the popularity of this kind of thing increases.


Regards
Alan

(in reply to hwaldron)
Post #: 2
RE: Clickjacking - What is it? - 10/21/2008 2:53:09 PM   
ndaniels


Posts: 191
Score: 32
Joined: 2/24/2006
From: The Republic of Elbonia
Status: offline
My understanding is that the best workaround for this is, from a browser perspective, is FireFox with NoScript.

(in reply to awenlock)
Post #: 3
RE: Clickjacking - What is it? - 10/21/2008 5:27:12 PM  1 votes
awenlock


Posts: 357
Score: 188
Joined: 3/8/2005
Status: offline
Yes, that's right.

There's a little write up here: http://www.pcadvisor.co.uk/news/index.cfm?RSS&NewsID=105510&pn=2

(in reply to ndaniels)
Post #: 4
RE: Clickjacking - What is it? - 10/22/2008 10:21:36 AM   
hwaldron


Posts: 3597
Score: 264
Joined: 9/12/2002
From: Roanoke VA, USA
Status: offline
My favorite security approach is to keep Flash disabled, as I've been doing for months now.  A few times I've had to toggle it on, (e.g.,. a legitimate need at a few sites and to test out releases of Adobe), but I always toggle it off immediately after I'm done.  I don't have Flash installed or active in my other browsers.

At work, keeping Flash disabled has actually improved my browsing experiences. I've found it's toned done Advertising extensively (predominant use of Flash)

While I have IE8 b2 on all my XP SP3 PCs, this also works for IE 7 ...

Adobe Flash - How to disable and enable in IE 7 or IE 8
http://msmvps.com/blogs/harrywaldron/archive/2008/05/30/adobe-flash-how-to-disable-and-enable-in-ie-7-or-ie-8.aspx


_____________________________


Harry Waldron - Security News & Best Practices Blog

(in reply to awenlock)
Post #: 5
RE: Clickjacking - What is it? - 10/22/2008 10:29:56 AM   
hwaldron


Posts: 3597
Score: 264
Joined: 9/12/2002
From: Roanoke VA, USA
Status: offline
P.S. Alan's article above points to a feature in the protective Firefox NoScript extension called "ClearClick"

QUOTE: NoScript, the security add-on for Firefox, has been upgraded to protect against clickjacking. The new improvement to NoScript, called ClearClick, can detect if there is a hidden, embedded element within the web page. It then displays a warning message asking the user if they still want to click on it. Maone said ClearClick will likely stop all clickjacking attempts. NoScript is only for the Firefox browser, so users of Microsoft's Internet Explorer - the most-used browser in the world - are vulnerable.


_____________________________


Harry Waldron - Security News & Best Practices Blog

(in reply to hwaldron)
Post #: 6
Page:   [1]
All Forums >> [Security, AntiVirus, and Patching] >> Breaking Virus & Security News >> Clickjacking - What is it? Page: [1]
Jump to:





New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts



  
Forum Software © ASPPlayground.NET Advanced Edition 2.4.5 ANSI

0.219