LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-17-2008, 01:37 PM   #1
evaluatinglinux
Member
 
Registered: Oct 2008
Posts: 45

Rep: Reputation: 15
Lightbulb Clickjacking.


Hi,
I was undergoing a security related training and the instructor mentioned an attack using an browser vulnerability/exploit called 'Clickjacking'

Man ... It was some really scary stuff that he demonstrated.
The malicious script simply takes hold of ur machines clipboard and never releases it. The only way out after clicking on a link or a simple mouse over (yes - it takes only that much to get infected!) is to reboot ur PC.


People ... Look up 'Clickjacking' on google. Better armed with knowledge than sorry!

Debian Kernel

Last edited by evaluatinglinux; 10-25-2008 at 02:54 AM.
 
Old 10-17-2008, 05:54 PM   #2
craigevil
Senior Member
 
Registered: Apr 2005
Location: OZ
Distribution: Debian Sid/RPIOS
Posts: 4,887
Blog Entries: 28

Rep: Reputation: 534Reputation: 534Reputation: 534Reputation: 534Reputation: 534Reputation: 534
NoScript for Firefox blocks this.

Quote:
# Improved usability and unobtrusivity of the unique ClearClick anti-Clickjacking technology, disabling user interaction with partially obstructed or not clearly visible embedded objects. Enabled by default on untrusted pages, you can configure it to work on trusted pages as well in NoScript Options|Plugins.
# New Forbid <FRAME> option for cross-site legacy frames, independent from Forbid <IFRAME>. Not to weaken IFRAME protection, legacy cross-site frames which are nested inside same-site IFRAMEs are blocked anyway.
 
Old 10-17-2008, 06:27 PM   #3
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Debian Testing
Posts: 19,192
Blog Entries: 4

Rep: Reputation: 475Reputation: 475Reputation: 475Reputation: 475Reputation: 475
I have moved this to Security as this would get more attention there.
 
Old 10-18-2008, 02:28 AM   #4
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by evaluatinglinux View Post
Hi,
I was undergoing a security related training and the instructor mentioned an attack using an browser vulnerability/exploit called 'Clickjacking'

Man ... It was some really scary stuff that he demonstrated.
The malicious script simply takes hold of ur machines clipboard and never releases it. The only way out after clicking on a link or a simple mouse over (yes - it takes only that much to get infected!) is to reboot ur PC.


People ... Look up 'Clickjacking' on google. Better armed with knowledge than sorry!
Could it be that you're confusing two completely separate vulnerabilities? What you have described above sounds more like an old Flash plugin vulnerability - not clickjacking. Clickjacking doesn't require Flash at all (or even JavaScript, for that matter). BTW, a heads-up about clickjacking was posted on our Mozilla Firefox Vulns thread last month.

Last edited by win32sux; 10-18-2008 at 02:31 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:36 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration