ClickJacking is a relatively old vulnerabilitiy that has been around since 2003-2004, however it has been recently brought back to life by Robert Hansen and Jeremiah Grossman. ClickJacking is a little bit difficult to explain however try to imagine any button that you see in your browser from the Wire Transfer Button on your Bank, Post Blog button on your blog, Add user button on your web-site etc. ClickJacking gives the attacker to ability to invisibly float these buttons on-top of other innocent looking objects in your browser. So when you try to click on the innocent object, you are actually clicking on the malicious button that is floating on top invisibly.
So while you are simply trying to close the javascript pop-up on your screen, play a flash game or interact with some ajax web-site -- you might really be clicking on the button to wire-transfer money to a russian bank account.
A slightly more technical description would be: A malicious page in domain A may create an IFRAME pointing to an application in domain B, to which the user is currently authenticated with cookies. The top-level page may then cover portions of the IFRAME with other visual elements to seamlessly hide everything but a single UI button in domain B, such as 'delete all items,' 'click to add Bob as a admin,' etc. It may then provide its own, misleading UI that implies that the button serves a different purpose and is a part of site A, inviting the user to click it.
In other words, the hacker would dupe users into visiting a malicious page -- through the usual methods -- but then hide the nasty bits under what appears to be the real-deal content from a legitimate site.
How Serious is ClickJacking?
On its own ClickJacking doesn't sound to be a very serious vulnerability, since user interaction is required. However as I have always said, in the world of vulnerabilities 1+1 does not always equal to 2, and might just equal to 10^2. By this I simply mean, that ClickJacking in combination with other vulnerabilities could become a very serious issue.
Example - ClickJacking can Spy on your Webcam and Microphone
Just as I wrote this blogpost a new use for ClickJacking has been disclosed where it can be used to spy on your Microphone and Webcam. This is based on a new vulnerability discovered in Adobe's Flash Software and published about on Guya.net, Rsnake's Blog and Jerremiah Grossman's Blog.
A particular vulnerability exists in Adobe's Flash Software, which allows the malicious attacker to use ClickJacking to gain access to the user's web-cam and microphone.
The vulnerability works as follows:
1) You visit a web-page with a flash application/game embedded in it.
2) You click on the flash button.
3) Your click is "click-jacked" into allowing the server to access your web-cam and microphone.
Whatis really happening:
1) You visit the web-page, in the back the target application (in this case Adobe's Settings Panel) is loaded and made invisible. The Allow button is made to float invisibly.
2) While you click on the flash button, the invisible Allow button is floating on top of the flash button and actually receives your click.
3) The Flash application now has full permission to access your web-cam, microphone etc and even have it stream to a server where it is recorded for future viewing.
Subscribe to:
Post Comments (Atom)
Counter
Labels
- About Domain Names (4)
- Android Hacks (2)
- Anti Yahoo booter (1)
- AOL hack (1)
- Broadband Hacking (5)
- Browser Tricks (1)
- Bsnl hack (1)
- Cell Phone Hacking (7)
- Computer hacks (24)
- Cracks/Serials (3)
- DataBase hacking (2)
- Defender (1)
- E-books for Hacking (4)
- Ethical hacking (15)
- Exciting Links.. (14)
- Facebook hack (2)
- FireFox hack (2)
- Free Downloadings (1)
- G-TALK Hacking (3)
- Gmail Hacking (2)
- Google Chrome (1)
- Google Hacking (2)
- Hack Airtel (5)
- Hack Vodafone (2)
- Hacking (62)
- Hotmail hack (3)
- Important Articles (16)
- Important Utility Softwares (35)
- Increase download speed (1)
- Innovations Articles (5)
- Intel Core i 7 (1)
- ip (2)
- ip hack (6)
- iPad (1)
- Key Logger (1)
- Lan Hacking (1)
- LInux (11)
- MegaUpload Hack (4)
- Mobile Hacks (14)
- Msn hacks (4)
- Nero (Linux) (1)
- Networking (6)
- Office (1)
- Operating Sysytems (24)
- Oracle 11g (2)
- Orkut goodies (3)
- Orkut Hacking (8)
- Password Hacking (6)
- phone unlocking (2)
- Programming softwares (3)
- Proxy (1)
- Proxy links (1)
- Rapid share hacks (10)
- Security (5)
- Skype hacking (1)
- Special Antiviruse (1)
- Theme for XP (3)
- Themes for Window 7 (1)
- Trojan (6)
- Usb Secuirty (3)
- Viruse (9)
- Website hacking (7)
- Windows 8 (2)
- Wireless Hacking (7)
- Xp Tweeks (5)
- Yahoo Hack (3)
- Yahoo messnger hack (6)
- You Tube Hack (1)
- Zapak hacking (4)
Followers
Blog Archive
-
▼
2009
(264)
-
▼
June
(61)
- New Airtel Hack for 100% free Sms
- Hack passwords with Cain and Abel
- How to find invisible users on Instant Messengers
- Rapidshare Premium link Generators (Unlimited down...
- Windows Vista Quattuor | 2.46 GBThis OS has been m...
- Windows Vista Black Eternity x86 (Genuine Version)
- 15 Tips to Improve your Linux Experience
- WEP Cracking, FBI Style( In Just 3 Minutes ) !
- Access Data of a Password Protected User in Window...
- How to safely uninstall Linux when Dual boot insta...
- How to convert Firefox into Fasterfox
- Gmail Account Hacking Tool
- Vodafone Hack for Free GPRS
- !!…Premium Accounts…!! { 16 Download Sites }
- DIY: Ripping off Windows XP using Backtrack Linux ...
- How do people boost download speed in LAN internet
- PicaSafe 2.0.207
- Nero (Linux)
- Virtual Plastic Surgery Software v.1.2
- SYMBIAN VIRUSES......
- Tools I Recommend -Must For All hackers
- The Viruse Make
- Latest Orkut hack(100% working)
- Samsung Mobile Service Center CODES
- Samsung D series hack
- Nokia All Codes
- MOTOROLLY CODES
- Mobile Secret Codes
- Mobile Cheat स्तुफ्फ NOKIA
- SAMSUNG SECRET CODES (NEW)
- BSNL hack for Internet
- Reliance Hack For free SMS
- Hack for Make FREE Calls.
- Hack Airtel Live to use Yahoo messenger for फ्री
- Mobile cheat codes fr all phones
- HowTo Use your mobile phone as a remote control fo...
- How to Make your own Linux
- Windows 7 Cheat Sheet
- Free Airtel GPRS using TeaShark Browser
- Connecting two buildings to one broadband service ...
- Build your own executable crypter
- Batch File To Disable Firewall-Windows Xp Sp2
- Tools to Automate rapid share Downloading
- Netcat Tips and Tricks
- Simple Batch Viruse explained
- How to create a backdoor using netcat
- Basics ARP Poison routing
- How does worm works
- WHAT IS CLICKJACKING
- Hack Airtel: Free Airtel Internet GPRS
- Airtel Hack for Broadband Internet- increase your ...
- Team Viewer
- Linux Mint 7 Gloria
- Why Is PCLinuxOS 2007 Better Than Ubuntu ?
- Invisible OS Boot Option - Hacking Grub
- Hacking an email
- How To Defend An Input Validation Attack
- For the Linux Novice
- Build your own network at home
- Autorun Viruse Killer!
- Make your USB drive free from virus
-
▼
June
(61)
Subscribe Via Email &Sms
Also Subscribe Via Sms Just click here to follow via
SMS
0 comments:
Post a Comment