ADMIN - Explore the new world of system administration! Special introductory offer! Order by September 30th to save 10% off the regular subscription price! Each issue delivers technical solutions to the real-world problems you face every day. Learn the latest techniques for better:
network security
system management
troubleshooting
performance tuning
virtualization
cloud computing
on Windows, Linux, Solaris, and popular varieties of Unix.
Counterfeit links are able to deceive the Firefox and Chrome browsers, directing users to unintended websites.
Aditya K Sood of Secniche Security has published an article which claims that Firefox and Chrome are vulnerable to a certain form of clickjacking. For example, if a user wants to go to Yahoo.com and clicks (unwittingly) on a forged link, an embedded JavaScript function redirects them to a totally different site.
Sometimes this will be obvious, but other times the user will be unaware of the detour until it is too late. When the mouse is passed over the link, the original address is shown in the address bar, i.e., Yahoo.com. Depending on the intentions of the hijackers, the bogus website can activate malignant codes, offer spam, or convince the user he/she is on the original website in order to elicit passwords. Users who want to know if the click trick works with their own browser can test it here. The source code enables the study of attacks.
A paper on clickjacking techniques is also available. Currently, the only protection against such an attack is to deactivate JavaScript.
(Kristian Kissling)
Comments
Et tu?
canadafreakazoid@gmail.com
Feb 02, 2009 10:54pm GMT
This must be 2009's most annoying meme: Clckjacking rumours
Get 3 Issues + 3 DVDs for the price of a single issue!
Let Linux Magazine's hands-on, technical articles guide you in your daily Linux use. Check out bonus DVDs like Ubuntu, SUSE, or Fedora and save the download.
Only available for a limited time. Don't miss out!
Comments
Et tu?
canadafreakazoid@gmail.com Feb 02, 2009 10:54pm GMT
This must be 2009's most annoying meme: Clckjacking rumourshttp://hackademix.net/2009/01/31/all-that-clickjazz/