Go Back   WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum
Register Blogs FAQ Social Groups CalendarHelp Desk

Reply
 
LinkBack Thread Tools
Old 09-26-2008, 01:23 PM   #1
Ancient&Decrepit Warrior
War Room Member
 
Michael Tracey's Avatar
 
Join Date: Jul 2002
Location: South Africa
Posts: 4,378
Thanks: 69
Thanked 167 Times in 23 Posts
Default ClickJacking... Scary stuff...

Heads up for those who haven't heard about it yet read Clickjacking: Researchers raise alert for scary new cross-browser exploit | Zero Day | ZDNet.com

Firefox users should also read Firefox + NoScript vs Clickjacking | Zero Day | ZDNet.com

IMHO Now would be a good time to install Noscript

Michael
Michael Tracey is online now   Reply With Quote
Old 09-27-2008, 02:26 AM   #2
Gatchaman fan
War Room Member
 
TheNightOwl's Avatar
 
Join Date: Sep 2008
Posts: 516
Blog Entries: 1
Thanks: 211
Thanked 88 Times in 53 Posts
Default Re: ClickJacking... Scary stuff...

Thanks for the heads up, Michael!

So I went over and read the article.

Then read a ton of the comments.

Got confused.

Installed NoScript anyway.

NoScript - JavaScript/Java/Flash blocker for a safer Firefox experience! - what is it? - InformAction

Good video here, too:



-----------------------------

There are (obviously!) some uber tech geeks on sites like ZDNet.

Sure, like any other place in InternetLand, there are people who don't know what they're talking about, but several posters in the "Comments" areas (a couple of threads are sort of interlinked) make good points.

For example, a couple of people lambaste the main article for being vague, asking "What, exactly, is this all about, then? And why do I need to worry? What's the big deal?"

And from my reading, I tend to agree. I can see that there's obviously an exploit, but the article didn't really make it clear to me just how malicious it could be.

I kind of feel the same as the poster of this thread:

Clickjacking: Researchers raise alert for scary new cross-browser exploit | TalkBack on ZDNet

Any techhead Warriors wanna spell it out for a bonehead?

-----------------------------

Some interesting comments in the threads:

Re: Flash being the problem...

Adobe Flash ads launching clipboard hijack attack | TalkBack on ZDNet

The video, above, shows you how to configure NoScript to deny Flash.

The thing I gleaned from a couple of the comments I read was that this browser hijack has happened through Flash banner ads on what might be considered trusted sites, such as Digg and CNN. So I'm wondering about the whitelisting option and whether it's effective.

Here's an example of several comments reitterating this point:
Clickjacking: Researchers raise alert for scary new cross-browser exploit | TalkBack on ZDNet

Obviously it's going to MORE effective in the sense that if you show up at some random page that you've never been to before, you don't know what you're going to find there and this will reduce the risk. For example, it could potentially be a domain that's been hijacked or simply an expired domain that previously had lots of traffic from inbound links and which has been purchased and loaded with Flash banners for porn sites or whatever.

In this case, if you deny Flash from running you're going to be safer.

And, I guess, any Flash content that you REALLY want to watch, you have to either decide if you want to Whitelist that site for good or choose the "Temporarily allow [site]" from the NoScript pop-up bar (as seen in the video, above).


Re: Admin priviledges

Firefox NoScript vs Clickjacking | TalkBack on ZDNet

The author of this post has made some very knowledgabe comments on this issue. I don't understand this one, though. I tried to do some digging, but didn't turn up much.

If someone here understands this, how about posting to help us out?

Cheers!

Thank you to everyone who contributed to the Global Giving Japanese Earthquake and Tsunami Relief Fund. I have friends in Japan, none of whom -- fortunately -- were affected. But lots of people are still doing it tough. So, thank you on their behalf.

TheNightOwl is offline   Reply With Quote
Old 09-27-2008, 03:57 AM   #3
Gatchaman fan
War Room Member
 
TheNightOwl's Avatar
 
Join Date: Sep 2008
Posts: 516
Blog Entries: 1
Thanks: 211
Thanked 88 Times in 53 Posts
Default Re: ClickJacking... Scary stuff...

Further quick question for existing NoScript users: Is there something I'm missing in the Options? Kern just sent out a vid. I clicked through. It obviously wouldn't show coz the default in NoScript is to not allow Flash. No problem. I click the icon. I select "Temporarily allow this site". No change. Can't for the life of me get that vid to run. Watched it in IE. Any ideas?

Thank you to everyone who contributed to the Global Giving Japanese Earthquake and Tsunami Relief Fund. I have friends in Japan, none of whom -- fortunately -- were affected. But lots of people are still doing it tough. So, thank you on their behalf.

TheNightOwl is offline   Reply With Quote
Old 09-27-2008, 04:08 AM   #4
It's in my Signature :-)
War Room Member
 
Josh Anderson's Avatar
 
Join Date: Nov 2003
Location: ID, USA.
Posts: 8,754
Blog Entries: 1
Thanks: 248
Thanked 990 Times in 443 Posts
Social Networking View Member's FaceBook Profile 
Default Re: ClickJacking... Scary stuff...

Surfing the web without flash and javascript?

Might as well unplug the computer and read a book.

At any rate I do not see the major issue...

What does it reach beyond them being able to make you click links if you visit a bad guy's page?

Can these links then "get you?"

Josh Anderson is offline   Reply With Quote
Old 09-27-2008, 04:10 AM   #5
Mindset for Success
War Room Member
 
Aaron Moser's Avatar
 
Join Date: Oct 2005
Location: California
Posts: 1,378
Thanks: 143
Thanked 87 Times in 45 Posts
Social Networking View Member's Twitter Profile 
Default Re: ClickJacking... Scary stuff...

NoScript Rocks! I wouldn't surf the internet without it.




Aaron Moser is offline   Reply With Quote
Old 09-27-2008, 09:04 AM   #6
HyperActive Warrior
 
Join Date: Sep 2008
Posts: 186
Thanks: 0
Thanked 3 Times in 3 Posts
Default Re: ClickJacking... Scary stuff...

I've been using ABP and Flash block for firefox. Surfing the internet feels so much cleaner and faster using these tools.

ahuddy is offline   Reply With Quote
Old 09-27-2008, 09:39 AM   #7
and his shiny metal ...
War Room Member
 
ThomM's Avatar
 
Join Date: Apr 2004
Location: 42.751109°N 73.408756°W
Posts: 1,407
Thanks: 528
Thanked 1,079 Times in 754 Posts
Social Networking View Member's FaceBook Profile  View Member's YouTube Profile
Default Re: ClickJacking... Scary stuff...

Quote:
Originally Posted by TheNightOwl View Post
Further quick question for existing NoScript users: Is there something I'm missing in the Options? Kern just sent out a vid. I clicked through. It obviously wouldn't show coz the default in NoScript is to not allow Flash. No problem. I click the icon. I select "Temporarily allow this site". No change. Can't for the life of me get that vid to run. Watched it in IE. Any ideas?
Next time try temporarily allow this page.
If the video is actually hosted on another site selecting allow this site won't work.
NoScript will also show you a list of what it is blocking and you can unblock anything on the list you want to allow.
I've been using NoScript for a long time and though it can be a pain at times I think it makes FF a lot safer and will keep on using it.

I Donated to KimW - give a sig link to Kim W
Life: Nature's way of keeping meat fresh
Always remember that you are unique. Just like everyone else.
No matter how deep the ocean is, you can still break a window with a hammer
Getting old ain't for sissy's
ThomM is offline   Reply With Quote
Old 09-27-2008, 09:42 AM   #8
Fanatic Warrior
 
najmiyusoff's Avatar
 
Join Date: Aug 2008
Location: Kuala Lumpur, Malaysia
Posts: 90
Thanks: 2
Thanked 2 Times in 1 Post
Contact Info
Send a message via Yahoo to najmiyusoff
Default Re: ClickJacking... Scary stuff...

ABP and Flash block eh? Gotta try it. Like Josh, I don't really understand the threat, but I'm not taking any chances anyway. Thanks for the heads up.


najmiyusoff is offline   Reply With Quote
Reply

  WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum

Tags
clickjacking, scary, stuff

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -6. The time now is 06:16 AM.