The Most Active and Friendliest
Affiliate Marketing Community Online!

“ActiveRevenue”/  “CPA

Flaw exposes Chrome and Firefox to clickjacking

D

djbaxter

Guest
Flaw exposes Chrome, Firefox to clickjacking
By Liam Tung, ZDNet Australia
Jan 29, 2009

Security researchers have discovered a flaw affecting Google's Chrome browser that exposes it to clickjacking ? where an attacker hijacks a browser's functions by substituting a legitimate link with a link of the attacker's choice.

Google has acknowledged the flaw and is working towards a patch for Chrome versions 1.0.154.43 and earlier when running within Windows XP SP2 systems, according to SecNiche security researcher Aditya K Sood.

...

While Google is working on a fix, a spokesperson for the Australian arm of the company pointed out that clickjacking affected all browsers, not just Chrome.

"The [clickjacking] issue is tied to the way the web and web pages were designed to work, and there is no simple fix for any particular browser. We are working with other stakeholders to come up with a standardized long-term mitigation approach," they said.

However, chief executive of Australian security consultancy Novologica, Nishad Herath, told ZDNet.com.au that after running Sood's proof of concept he found that Internet Explorer 8 (release candidate 1 and beta 2 versions) and Opera 9.63 (the latest version) were not exposed to the flaw. But, like Chrome, Firefox 3.0.5 was exposed.

...more
 
It's a problem with IE too. Unless they've just recently patched it.

It's a cross browser vulnerability and it's scary because they use it to take your banking info and other logins.

Here's a VERY detailed post with lots of info.

http://affiliate-marketing-forums.5...rning-disable-browser-plug-ins.html#post40169

One solution as mentioned in the post above is to use disable all plug-ins and use Firefox and the NoScript plugin. I've been using for months. It's a bit of a pain to get used to as it blocks lots of things you want to do every day - even videos. But you just click temporarily allow all if you if you are on a trusted site.
 
According to ZDNet, neither IE8 nor Opera 9.63 are vulnerable.

However, it's true that earlier versions of IE and Opera may be vulnerable.
 
banners
Back