Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg

Clickjacking Threat To Firefox

Jan 30, 2009

Counterfeit links are able to deceive the Firefox and Chrome browsers, directing users to unintended websites.

Aditya K Sood of Secniche Security has published an article which claims that Firefox and Chrome are vulnerable to a certain form of clickjacking. For example, if a user wants to go to Yahoo.com and clicks (unwittingly) on a forged link, an embedded JavaScript function redirects them to a totally different site.

Sometimes this will be obvious, but other times the user will be unaware of the detour until it is too late. When the mouse is passed over the link, the original address is shown in the address bar, i.e., Yahoo.com. Depending on the intentions of the hijackers, the bogus website can activate malignant codes, offer spam, or convince the user he/she is on the original website in order to elicit passwords.
Users who want to know if the click trick works with their own browser can test it here. The source code enables the study of attacks.

A paper on clickjacking techniques is also available. Currently, the only protection against such an attack is to deactivate JavaScript.

(Kristian Kissling)

Comments

Et tu?

canadafreakazoid@gmail.com Feb 02, 2009 10:54pm GMT

This must be 2009's most annoying meme: Clckjacking rumours

http://hackademix.net/2009/01/31/all-that-clickjazz/

Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg
Related Articles
From 3.1 to 3.5: Version leap for Firefox?
Mozilla Closes Down Critical Security Holes
Mozilla Asks for License Integration into Ubuntu
Insecure Candidates: Chrome Wins Hacking Contest
Mozilla Developers Remove Critical Bugs
Mozilla Responds to the EULA Controversy
No More Downloads!

Save the download and take Linux Magazine DVDs instead.

Each DVD contains a full distro like Ubuntu, SUSE, Mandriva, Fedora, or Debian and comes with the corresponding issue of Linux Magazine.

Don't waste timedownloading Linux!

more...

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2009 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux Technical Review]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland] [Open Source DVD Poland]
International: [Linux Magazine Brazil] [EasyLinux Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]