Spotlight | Reviews | Current Issue | Academy | Newsletter | Subscribe | Shop |
Departments

Partner Links
Make your own website
WinWeb OnlineOffice
Comparing prices of hardware is worth it.
Price Comparison
What:
Where:
Country:
vacatures Netherlands njobs Linux vacatures
arbeit Deutschland njobs Linux arbeit
work United Kingdom njobs Linux jobs
Lavoro Italia njobs Linux lavoro
Emploi France njobs Linux emploi
trabajo Espana njobs Linux trabajo

user friendly

Admin Magazine

ADMIN Network & Security

Subscribe now and save!

 ADMIN - Explore the new world of system administration! ADMIN is a smart, technical magazine for IT pros on heterogeneous networks. Each issue delivers technical solutions to the real-world problems you face every day. Learn the latest techniques for better:

  • network security
  • system management
  • troubleshooting
  • performance tuning
  • virtualization
  • cloud computing

 on Windows, Linux, Solaris, and popular varieties of Unix.

http://www.admin-magazine.com/

  linux-magazine.com » Online » News » Clickjacking Threat To Firefox  

Print this page. Recommend
Share

Clickjacking Threat To Firefox

Counterfeit links are able to deceive the Firefox and Chrome browsers, directing users to unintended websites.

Aditya K Sood of Secniche Security has published an article which claims that Firefox and Chrome are vulnerable to a certain form of clickjacking. For example, if a user wants to go to Yahoo.com and clicks (unwittingly) on a forged link, an embedded JavaScript function redirects them to a totally different site.

Sometimes this will be obvious, but other times the user will be unaware of the detour until it is too late. When the mouse is passed over the link, the original address is shown in the address bar, i.e., Yahoo.com. Depending on the intentions of the hijackers, the bogus website can activate malignant codes, offer spam, or convince the user he/she is on the original website in order to elicit passwords.
Users who want to know if the click trick works with their own browser can test it here. The source code enables the study of attacks.

A paper on clickjacking techniques is also available. Currently, the only protection against such an attack is to deactivate JavaScript.

(Kristian Kissling)

Comments

Et tu?

canadafreakazoid@gmail.com Feb 02, 2009 10:54pm GMT

This must be 2009's most annoying meme: Clckjacking rumours

http://hackademix.net/2009/01/31/all-that-clickjazz/

Print this page. Recommend
Share
Related Articles
Mozilla Evangelist Comments on Apple's Recent HTML5 Demos
Firefox 4 Beta Loves HTML5
Firefox 2.0.0.9 Corrects Latest Release
Competition Announced: Calling all Firefox Mobile Add-on Developers
Update Recommended: Firefox 3.0.8
Firefox Home Approved, Available in App Store
Get your backstage pass to Linux!

If you're ready for a deeper look, Linux Magazine gives you a view behind the scenes.

Don't miss out on the tools, tutorials, and reviews you'll need to unlock the secrets of Linux.

more...