Print | Send on Yahoo! | PDF version | Feed RSS | Filed Under: MISCELLANEOUS

Adobe has finally released an advisory on the "clickjacking" issue

Date: 10/09/2008
Author: Razvan Stoica

Adobe has finally released an advisory on the "clickjacking" issue, while a random flash hacker posted on his or her blog a proof of concept which uses this procedure.

Clickjacking is not an exploit in the traditional sense, in that the affected technology (DHTML) is used, working as intended, and no software "bugs" are used to trigger it either. The PoC activates the user's camera and microphone and leeches off them (both are features thoughtfully provided by Adobe Flash, which get activated by the user clicking on a button that looks like one thing but is another entirely).

"Coincidentally", both events (the advisory release and the PoC release) took place on October 7th, once again underlining the importance and community benefits of pressuring vendors into Doing The Right Thing. Indeed, to the uninitiated it would appear that Adobe took the road more travelled and effectively sat on the patch until it was forced to release it and thus admit to having made a mistake sometime in the past.

Those of you who aren't following this column (for shame!) will be interested to find out that Adobe had in fact pressured the two researchers who dreamed up "clickjacking" into not publicizing details of the exploit.

On an unrelated note, it's pretty sad to see that the "clickjacking" concept/meme is gaining traction - it's just a trick with frames, the likes of which have been known since time immemorial.


Share our story:
DiggStumbleUpondel.icio.usYahooMyWebFurlGoogle

Comment on this:
Name:
Email:
Your email address will not be published!

Please enter the code from the image below.
The code is not case sensitive
Verification Image
Reload image
 
 
Calendar
March 2010
MoTuWeThFrSaSu
1234567
891011121314
15161718192021
22232425262728
293031    
« Feb March Apr »
Tag Claud
system twitter file messages security malware exploit worm data canadian windows spam conficker rogue online bitdefender files infected omelette downadup pharmacy review word microsoft trojan message software computer antivirus virus