• On The Insider: Britney's Bikini-Clad Top 10
February 13, 2009 11:46 AM PST

Twitter fends off second clickjacking attack

by Elinor Mills

Twitter fended off a second clickjacking attack on Thursday night as the popular microblogging site plays cat-and-mouse with a prankster, the site confirmed on Friday.

"Yes, there was a second approach later in the day, same story as the first but with a slightly modified technique," Twitter co-founder Biz Stone wrote in an e-mail. "We took care of that too. Every day we're finding ways to improve the system."

(Credit: CNET Networks)

"It's a convoluted cat-and-mouse game," Jeremiah Grossman, chief technology officer of WhiteHat Security, said earlier on Friday. "At least for the moment, Twitter is winning."

Twitter users first noticed the clickjacking prank on Thursday and later that day Twitter had shut it down. Tweets were popping up that said "Don't Click" followed by a link. Clicking the link took the user to a page that included a button that said "Don't Click." Clicking the button automatically distributed the identical tweet. As you can imagine, this spread pretty quickly.

Later on Thursday, the tweets started appearing again after someone figured out a way around Twitter's fix, said Grossman.

Basically, the clickjacking page with the "Don't Click" button on it has an invisible frame with a Twitter status update button superimposed over it, he said. Twitter's original fix wiped a page clean if it detected a frame on its pages, but then someone circumvented that and Twitter was forced to come up with another fix, according to Grossman.

The clickjacking is likely a harmless experiment, but it could be used for malicious purposes in the future, Grossman said.

Firefox users can download a no-script extension to protect against clickjacking but current versions of Internet Explorer do not offer protection, although IE 8 will, he said.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
advertisement
Click here!
Recent posts from Security
Microsoft to fix holes in Windows, Office
Google privacy controls: Most people won't care
Zero-day flaw found in Web encryption
Mac Game: Art project or malware?
Corporate bank accounts targeted in online fraud
Hacker breaks into jailbroken iPhones, asks for $7
Malwarebytes accuses rival of software theft
Security firm M86 acquires Finjan
Add a Comment (Log in or register)
by Alhan_Keser February 14, 2009 8:40 AM PST
"current versions of Internet Explorer do not offer protection"

What a surprise.
Reply to this comment
by bluemudkipz February 20, 2009 11:34 PM PST
I've found NoScript very frustrating because I don't know much about programming. You could go with Block All Scripts, but it renders pretty much everything fun on the Internet useless. Obviously the best way to go is to selectively allow scripts, but I just haven't had the time to sit down, dig out all the scripts that my computer can be exposed to safely, and allow them.
But that's just what I feel after about ten minutes of having the add-on, so if there's a way around doing all that, please enlighten me. I'd really like to use it.
Reply to this comment
advertisement

FAQ: Buying the right Windows 7 upgrade

Readers still have lots of questions on just which version of the software they need to buy in order to upgrade their PC. CNET News tries to offer some answers.

N.Y. lawsuit details Intel's 'largesse' toward Dell

Attorney General Andrew Cuomo's federal antitrust case filed Wednesday alleges a longstanding symbiotic relationship between Intel and Dell.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement
Click Here

Inside CNET News

Scroll Left Scroll Right