Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Clickjacking - anyone use photobucket?

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
Deja Q Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Nov-20-08 01:38 PM
Original message
Clickjacking - anyone use photobucket?
Trend Antivirus reported a possible clickjacking attempt while uploading a pic.

May be a red herring, but wanted to throw out a cheap warning.

Printer Friendly | Permalink |  | Top
crim son Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Nov-20-08 01:44 PM
Response to Original message
1. What is "clickjacking"?
Eh?
Printer Friendly | Permalink |  | Top
 
flvegan Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Nov-20-08 01:46 PM
Response to Reply #1
2. Using a second, more powerful remote than your mate has for the tv
Printer Friendly | Permalink |  | Top
 
crim son Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Nov-20-08 01:48 PM
Response to Reply #2
3. Ah, see. I have no mate,
and I don't watch t.v., hence my confusion, Freak. :P
Printer Friendly | Permalink |  | Top
 
Bertha Venation Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Nov-20-08 03:55 PM
Response to Reply #2
4. LOL
:thumbsup:

Oh, wait - is that really it? Either way, it's funny.
Printer Friendly | Permalink |  | Top
 
BrklynLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Nov-20-08 04:05 PM
Response to Reply #1
5. Try this..
Edited on Thu Nov-20-08 04:11 PM by BrklynLiberal
http://blogs.zdnet.com/security/?p=1972

In a nutshell, it’s when you visit a malicious website and the attacker is able to take control of the links that your browser visits. The problem affects all of the different browsers except something like lynx. The issue has nothing to do with JavaScript so turning JavaScript off in your browser will not help you. It’s a fundamental flaw with the way your browser works and cannot be fixed with a simple patch. With this exploit, once you’re on the malicious web page, the bad guy can make you click on any link, any button, or anything on the page without you even seeing it happening.

Ebay, for example, would be vulnerable to this since you could embed javascript into the web page, although, javascript is not required to exploit this. “It makes it easier in many ways, but you do not need it.” Use lynx to protect yourself and don’t do dynamic anything. You can “sort of” fill out forms and things like that. The exploit requires DHTML. Not letting yourself be framed (framebusting code) will prevent cross-domain clickjacking, but an attacker can still force you to click any links on their page. Each click by the user equals a clickjacking click so something like a flash game is perfect bait.



http://www.schneier.com/blog/archives/2008/10/clickjacking.html
In plain English, clickjacking lets hackers and scammers hide malicious stuff under the cover of the content on a legitimate site. You know what happens when a carjacker takes a car? Well, clickjacking is like that, except that the click is the car.

"Clickjacking" is a stunningly sexy name, but the vulnerability is really just a variant of cross-site scripting. We don't know how bad it really is, because the details are still being withheld. But the name alone is causing dread.


http://www.webmonkey.com/blog/A_Look_at_the__Clickjacking__Web_Attack_and_Why_You_Should_Worry
Printer Friendly | Permalink |  | Top
 
redqueen Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Nov-20-08 05:12 PM
Response to Original message
6. Thanks for the warning, HT.
And for the details, BrklynLiberal.

Sheesh... what makes people act like this I wonder.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Tue Apr 23rd 2024, 06:20 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC