Comments on: Clickjacking: Hijacking clicks on the Internet
Security researcher warns that clicking on the Web may not always take you where you want to go.
Security researcher warns that clicking on the Web may not always take you where you want to go.
Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.
Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.
Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.
Add this feed to your online news reader
But here you see I hate that and makes me livid! I did not click a darn thing on some website but I just sit there doing nothing then I hear a click sound.
I call that "MOUSE CLICK IMPERSONATION" and that should be illegal!
What this means is that if some local joe on his pc late at night sees some adult material and he just faps to that page then evil porn advertisers force a click to an illegal under age website then this local joe is responsible for pedophilia on his computer and he did nothing but visit a soft porn website.
So you can hear it on windowsupdate and on other sites and just just from microsoft and porn sites.
This really makes me sick and one day I was not even on a porn site but just some rated G chat room talkign about pc hard ware and while I type with 5 minutes I heard over 42 clicks!
ENOUGH ALREADY! Oh and yes my pc was clean and virus,trojan,spyware,malware free.
I am sick sick sick sick sick of this.
NoScript addon with Firefox alerts you to ClickJacking.
http://blogs.adobe.com/jd/2009/05/cnet_clickjacking_comment.html
Furthermore the larger clickjacking issue in the browser security realm is brought to the forefront by the recent events that have transpired on Twitter. This is just a taste of what I and many others believe is yet to come. We failed to take XSS, CSRF, and SQL Injection seriously years back when we first knew about them and look where we are today. I?d prefer clickjacking not be ignored until something truly bad happens.
omg is new source these days this bad!....
BoBBy- B@ bolinousa@msn.com
BoBBy-B @ bolinousa@msn.com
It almost seems like all vulnerabilities out there come from Microsoft.
For a more complete discussion on this topic, check out http://www.owasp.org/index.php/Clickjacking
OWASP also offers FOSS Java-based filters to automatically afford this kind of protection for Java-based websites in the enterprise. See http://www.owasp.org/index.php/ClickjackFilter_for_Java_EE
This is a solution? You might as well disconnect your cable/modem line. Result would be just about the same. No one seems capable of programming a website without Javascript/ActiveX/Flash anymore. I set ActiveX to notify and most usually click NO and that gives me headaches enough. Turning off javascript would make browsing pretty much impossible. Do the people who suggest these inane things even try their own suggestions? Geesh.
(Haha. Count CNET as one of those that BREAKS when you don't allow Active X. The Comment Submit button doesn't work without it. Had to reload the page and allow Active X. I'm not even going to try it with Javascript turned off. Probably wouldn't be able to see the page at all.)
- by AnthonyNYC May 28, 2009 3:46 PM PDT
- He never said this was a browser specific or Operating system specific problem, he said any browser using CSS ( Cascading Style Sheets) is vulnerable, Mac and PC! Simple, just listen
- Like this Reply to this comment
-
(27 Comments)