Spotlight | Reviews | Current Issue | Newsletter | Subscribe | Contact |
Departments

Partner Links
Website builder
WinWeb OnlineOffice
Shopping and price comparison with product reviews at dooyoo.co.uk

user friendly

CeBIT 2010 CFP

Linux Magazine is offering free booths for the CeBIT 2010 computer fair to selected open source projects. Apply Now!

  linux-magazine.com » Online » News » Clickjacking Threat To Firefox  

Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg

Clickjacking Threat To Firefox

Counterfeit links are able to deceive the Firefox and Chrome browsers, directing users to unintended websites.

Aditya K Sood of Secniche Security has published an article which claims that Firefox and Chrome are vulnerable to a certain form of clickjacking. For example, if a user wants to go to Yahoo.com and clicks (unwittingly) on a forged link, an embedded JavaScript function redirects them to a totally different site.

Sometimes this will be obvious, but other times the user will be unaware of the detour until it is too late. When the mouse is passed over the link, the original address is shown in the address bar, i.e., Yahoo.com. Depending on the intentions of the hijackers, the bogus website can activate malignant codes, offer spam, or convince the user he/she is on the original website in order to elicit passwords.
Users who want to know if the click trick works with their own browser can test it here. The source code enables the study of attacks.

A paper on clickjacking techniques is also available. Currently, the only protection against such an attack is to deactivate JavaScript.

(Kristian Kissling)

Comments

Et tu?

canadafreakazoid@gmail.com Feb 02, 2009 10:54pm GMT

This must be 2009's most annoying meme: Clckjacking rumours

http://hackademix.net/2009/01/31/all-that-clickjazz/

Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg
Related Articles
Mozilla Developers Remove Critical Bugs
Mozilla Responds to the EULA Controversy
Firefox 3.0.5 and 2.0.0.19 Tackle Security Problems
Update Recommended: Firefox 3.0.8
Security Bug in Konqueror, Updates for Seamonkey & Co
Next Firefox 3 Beta
Rikki's Open Source Exchange

Stop by Rikki's Open Source Exchange for dispatches from the world of women in open source.

Rikki Kite examines the experience of women across the spectrum of open source –
the people, projects, organizations, events, articles, issues, and news.

more...

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2009 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux Technical Review]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland] [Open Source DVD Poland]
International: [Linux Magazine Brazil] [EasyLinux Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]