Newsletter:

Skip Navigation LinksHome > News > Security > Adobe warns of ‘clickjacking’ attacks

Adobe warns of ‘clickjacking’ attacks

By Iain Thomson
9 October 2008 03:21PM
Tags: adobe | browsers | clickjacking

Adobe has issued a security alert about its Flash software that makes it vulnerable to being abused by hackers in a practice known as clickjacking.

Clickjacking involves subverting a web page so that when a visitor clicks on a link they are redirected to a site the hackers wants them to see. It is a variant of cross-site scripting attacks but appears to be more serious.

The details of the attack were due to be published at the OWASP NYC AppSec 2008 Conference but the talk was withheld at Adobe’s request until a workaround could be developed. The reportis available online.

“Let’s be clear though, the responsibility of solving clickjacking does not rest solely at the feet of Adobe as there is a ton of moving parts to consider,” said Jeremiah Grossman, co-founder of Whitehat Security and one of the researchers who uncovered the technique.

“Everyone including browser vendors, Adobe (plus other plug-in vendors), website owners (framebusting code) and web users (NoScript) all need their own solutions to assist incase the other don’t do enough or anything at all.”

He warns that almost all browsers are vulnerable because of the way they process graphics and only text-based browsers like Lynx are secure.

Grossman has demonstrated for example how a hacked Flash advert can be used to take over control of a computer’s webcam and microphone, turning it into a surveillance device.

“With Clickjacking attackers can do quite a lot. Some things that could be pretty spooky. Things also performed, with a fair amount of ingenuity, quite easily,” he said.

US-CERT has also issued a warning on the practice and browser manufacturers are scrambling to come up with a method of defeating the attacks.

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The AdventNet Manage-Engine Password Manager Pro provides a complete system for password management in one...
Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Unified Communications Podcast Centre

TopTopics
(6540) -  internet
(6411) -  iinet
(6386) -  copyright
(6386) -  afact
(5987) -  servers
(5987) -  mipi
(4749) -  telstra
(4438) -  broadband
(4401) -  nbn
(2811) -  internode
(2372) -  microsoft
(1874) -  network
(1445) -  data
(1361) -  google
(1263) -  centre