Search
Joe Pruitt - A Software Architect's take on Network Security
You are here: DevCentral > Weblogs

posted on Friday, October 10, 2008 9:34 AM

MouseClick Worried about losing your personal information?  Yep, me too!  The updated FireFox plugin NoScript aims to thwart the recently discovered ClickJacking class of browser based security exploits.

Less than a month ago a new class of browser based security exploits were discovered that allows an attacker to get you to click on a button without your knowledge thus executing malicious code or inadvertently exposing personal information.

Robert Hansen of SecTheory LLC and Jeremiah Grossman of WhiteHat Security Inc coined the term "ClickJacking".  From Jeremiah Grossman:

start_quote Think of any button on any Web site, internal or external, that you can get to appear between the browser walls. Wire transfers on banks, Digg buttons, CPC advertising banners, Netflix queue, etc. The list is virtually endless and these are relatively harmless examples. Next, consider that an attack can invisibly hover these buttons below the users' mouse, so that when they click on something they visually see, they actually are clicking on something the attacker wants them to. end_quote

The recommended protection at this point is to use FireFox with the NoScript plugin that enables frame/plug-in blocking.

noscript-2 But, the latest version of NoScript goes one step further with a new feature called "ClearClick" specifically aimed at protecting users against ClickJacking attacks.

start_quote Rather than relying on frame/plug-in blocking, which were already available, I decided to move on and add a brand new feature, developed from scratch, for people who couldn't bear blocking frames outright, end_quote said Italian developer and security researcher Giorgio Maone in an interview on Computerworld.com. 

In his blog, Maone spelled out what ClearClick does in greater detail:

start_quote Whenever you click or otherwise interact, through your mouse or your keyboard, with an embedded element which is partially obstructed, transparent or otherwise disguised, NoScript prevents the interaction from completing and reveals to you the real thing in 'clear'.  At that point, users can decide for themselves whether to continue clicking, or free up the mouse from underlying, and potentially exploitive, content. end_quote

So, don't wait, hop on over to the Mozilla AddIns site and protect yourself with NoScript.

As a side note, we had a great podcast a while ago with Jeremiah Grossman that you might want to check out!

-Joe


Posted In: Security, ISV Solutions,

Feedback

10/20/2008 9:58 AM
Gravatar ClickJacking Your Way Into Office
Joe Pruitt
7/29/2009 5:17 AM
Gravatar thanks for the ClickJacking avoidance tips - vnice
comic

Let Me Know What You Think


Please use the form below if you have any comments, questions, or suggestions.

Title:
 
Name:
 
Email: (so we can show your gravatar)
Website:
Comment: Allowed tags: blockquote, a, strong, em, p, u, strike, super, sub, code
 
Please add 7 and 5 and type the answer here:

Blog Stats

Posts:379
Comments:1067
Stories:1
Trackbacks:301
  

Article Categories

  iRules
  

Image Galleries

  

Joe's bookshelf: read

The Lost Gate
4 of 5 stars
This one started slow but I got really got into it about 1/3 of the way through. If you are an Ender's Game fan, you'll probably like this one as well.

goodreads.com


82,243 Members in 102 Countries and Growing!

Join DevCentral Today!

About DevCentral

DevCentral has been a successful, thriving community for many years. We have always strived to bring you the best technical documentation, discussion forums, blogs, media and much more that we can.

So dive in, get familiar with DevCentral. We hope you like it, we hope it makes your job easier, and lets you get that much more power out of the community. To learn more, make sure to check out the Getting Started section. And if you have any problems, or think something could be easier to use, drop us a line to let us know.

Got It !

We've received your comment and transmitted it directly to DevCentral HQ.

Thanks for taking time to let us know what's on your mind. At DevCentral | Community Matters!

Get In Touch With Us

Have questions, suggestions or just want to get something off your chest?

Use our handy form below to Direct Connect with DevCentral Mission Control.

Send Us Feedback       or