Skip to main content

Clickjacking "Browser Exploit"

Clickjacking is a term used by two security experts Robert “RSnake” Hansen and Jeremiah Grossman to define a new major web attack that could potentially affect millions of web users.This threat exploits the bug that is present in "One of the Adobe products" but Jeremiah and Robert believe that the clickjacking flaw ultimately lies in the way that Internet browsers are designed.According to Grossman
"If I control what you click on, how much bad can I do? It turns out you can do a number of really, really bad things."

What makes the attack noteworthy is that this attack is compatible with all browsers and their all versions be it Firefox,IE,Opera,Safari or any other browser.Jeremiah and Robert were going to demonstrate this attack on Open Web Application Security Project (OWASP) in New York City this week but on Adobe's request they postponed their demonstration so that the Adobe can contact all web browser vendors and can release a patch for this exploit.

The Approach:: In a clickjacking attack, the attacker tricks the victim into clicking on malicious Web links without realizing it. This type of attack has been known for years, but had not been considered to be particularly dangerous.However, in writing their proof-of-concept code, Hansen and Grossman realized that clickjacking was actually more serious than they'd first thought.

The Demo::
A small demo of this exploit can be seen on this link (this is just a temporary demo and will not affect your system).Open the link and then open anything on your same web browser and copy some data and try to paste it anywhere.What you see.Now to recover from this just restart your web browser.This demo is a "clipboard hijack" demo and exploits the clipboard.There can be many other types of possible hijack too.

But how much "bad" this exploit can get and how is attack work is still a question that needs to be answered and when are they going to disclose it because releasing the patches will take time .So either we should just "wait and watch" or search out by our own.If any one gets some info then just push a comment on this blog.

Links to check::
ars technica
Adobe's confirmation

Comments

Popular posts from this blog

Future of AI

  The Future of Artificial Intelligence Artificial intelligence (AI) is one of the most important technologies of our time. It is already having a major impact on our lives, and its influence is only going to grow in the years to come. AI is already being used in a wide variety of applications, including: Natural language processing: AI is used to understand human language, which is essential for applications like speech recognition and machine translation. Image recognition: AI is used to identify objects and patterns in images, which is used in applications like facial recognition and self-driving cars. Machine learning: AI is used to train machines to learn from data, which is used in applications like fraud detection and spam filtering. These are just a few examples of the many ways that AI is being used today. As AI continues to develop, it will be used in even more applications, and its impact on our lives will only grow. So what does the future hold for AI? Here are a few predic

Karnataka Elections 2023: The Handslide

  The Congress party won the 2023 Karnataka Legislative Assembly election by a landslide, winning 126 seats and forming the government. The BJP, which was in power for the last five years, was reduced to 39 seats. The Janata Dal (Secular) won 37 seats. There were several reasons for the Congress's victory. One reason was the anti-incumbency factor. The BJP had been in power for five years, and there was a lot of dissatisfaction with the government's performance. The Congress was able to capitalize on this dissatisfaction and win over many voters. Another reason for the Congress's victory was its strong local leadership. The party had a strong organization in Karnataka, and it was able to mobilize its supporters effectively. The BJP, on the other hand, was seen as being out of touch with the people of Karnataka. The Congress also benefited from the fact that it was able to project a more secular image than the BJP. The BJP has been accused of being too close to the Hindutva

Are CRED Rewards a Sham?

  CRED is a fintech startup that offers a credit card bill payment app. The app is designed to make it easier for users to pay their credit card bills on time and earn rewards. However, there are some concerns that CRED may not be good for consumers. One concern is that CRED encourages users to spend more money than they can afford. The app uses gamification and social media to create a sense of competition among users. This can lead to users spending more money in order to climb the leaderboard and earn rewards. Another concern is that CRED's rewards program is not as generous as it may seem. In order to earn the most rewards, users need to pay their credit card bills on time and in full. However, many users may not be able to do this, especially if they are struggling to make ends meet. Finally, CRED's privacy policy has been criticized for being too vague. The policy states that CRED may share user data with third-party partners, but it does not specify which partners or wha