SUBSIM Radio Room Forums



SUBSIM: The Web's #1 resource for all submarine & naval simulations since 1997

Go Back   SUBSIM Radio Room Forums > General > General Topics
Forget password? Reset here

Reply
 
Thread Tools Display Modes
Old 10-08-08, 07:58 PM   #1
Syxx_Killer
Admiral
 
Join Date: Aug 2003
Location: Michigan, USA
Posts: 2,387
Downloads: 21
Uploads: 0
Now we can be "clickjacked"

http://news.yahoo.com/s/nf/20081008/bs_nf/62355

As if adware, spyware, viruses, trojans, homepage hijackers, and other malware weren't enough. Now we can evidently be clickjacked. All I want to do is browse the web without worrying about which of the numerous cases mentioned above I can get infected with. Is that too much to ask?
Syxx_Killer is offline   Reply With Quote
Old 10-08-08, 08:09 PM   #2
SUBMAN1
Rear Admiral
 
Join Date: Apr 2005
Posts: 11,866
Downloads: 0
Uploads: 0
Default

Simple solution - run Firefox and install noscript and adblock on it. Then no worries for you on any of these exploits.

-S
__________________
SUBMAN1 is offline   Reply With Quote
Old 10-08-08, 08:23 PM   #3
SteamWake
Rear Admiral
 
Join Date: Mar 2005
Posts: 13,224
Downloads: 5
Uploads: 0
Default

Did you even read the article?

Quote:
Clickjacking has been identified as a vulnerability for the Adobe Flash player, as well as for every major browser, including Firefox, Internet Explorer, Opera, Safari and even the newly released Google Chrome
Meh... its an adobe issue anyhow.
SteamWake is offline   Reply With Quote
Old 10-08-08, 08:25 PM   #4
Task Force
Rear Admiral
 
Join Date: Jul 2008
Location: SPACE!!!!
Posts: 10,142
Downloads: 85
Uploads: 0
Default

Then dont use Adobe for anything, even games.
__________________
Task Force industries "Taking control of the world, one mind at a time"
Task Force is offline   Reply With Quote
Old 10-08-08, 08:28 PM   #5
SUBMAN1
Rear Admiral
 
Join Date: Apr 2005
Posts: 11,866
Downloads: 0
Uploads: 0
Default

Quote:
Originally Posted by SteamWake
Did you even read the article?

Quote:
Clickjacking has been identified as a vulnerability for the Adobe Flash player, as well as for every major browser, including Firefox, Internet Explorer, Opera, Safari and even the newly released Google Chrome
Meh... its an adobe issue anyhow.
Yes, and no script script blocker will block it. Try it already.

-S
__________________
SUBMAN1 is offline   Reply With Quote
Old 10-08-08, 08:31 PM   #6
Task Force
Rear Admiral
 
Join Date: Jul 2008
Location: SPACE!!!!
Posts: 10,142
Downloads: 85
Uploads: 0
Default

So it will affect Mac too.
__________________
Task Force industries "Taking control of the world, one mind at a time"
Task Force is offline   Reply With Quote
Old 10-08-08, 09:33 PM   #7
SandyCaesar
Chief
 
Join Date: Jul 2008
Location: HMS Thanatus
Posts: 325
Downloads: 0
Uploads: 0
Default

Looks scary, but I have to agree with SUBMAN1. It's Flash-based...which means that NoScript should be able to stop it flat, unless you, for some reason, enable it. Or unless you're running IE/Safari/Chrome, but it's a fair bet that there'll be NoScript analogues for those browsers out soon, if not now.
__________________

Vanvikan, Feb. 2009: ordinary human, KIA, night 4



HMS Thanatus, May 2009: ??? human, KIA, night 7
SandyCaesar is offline   Reply With Quote
Old 10-08-08, 10:39 PM   #8
mookiemookie
Navy Seal
 
mookiemookie's Avatar
 
Join Date: Nov 2005
Location: Houston, TX
Posts: 9,404
Downloads: 105
Uploads: 1
Default

Quote:
Originally Posted by SUBMAN1
Quote:
Originally Posted by SteamWake
Did you even read the article?

Quote:
Clickjacking has been identified as a vulnerability for the Adobe Flash player, as well as for every major browser, including Firefox, Internet Explorer, Opera, Safari and even the newly released Google Chrome
Meh... its an adobe issue anyhow.
Yes, and no script script blocker will block it. Try it already.

-S
Not quite:

Quote:

According to someone who attended the semi-restricted OWASP presentation, the issue is indeed zero-day, affects all the different browsers and has nothing to do with javascript:
  • In a nutshell, it’s when you visit a malicious website and the attacker is able to take control of the links that your browser visits. The problem affects all of the different browsers except something like lynx. The issue has nothing to do with JavaScript so turning JavaScript off in your browser will not help you. It’s a fundamental flaw with the way your browser works and cannot be fixed with a simple patch. With this exploit, once you’re on the malicious web page, the bad guy can make you click on any link, any button, or anything on the page without you even seeing it happening.
http://blogs.zdnet.com/security/?p=1972
__________________
They don’t think it be like it is, but it do.

Want more U-boat Kaleun portraits for your SH3 Commander Profiles? Download the SH3 Commander Portrait Pack here.
mookiemookie is offline   Reply With Quote
Old 10-08-08, 11:01 PM   #9
SUBMAN1
Rear Admiral
 
Join Date: Apr 2005
Posts: 11,866
Downloads: 0
Uploads: 0
Default

Quote:
Originally Posted by mookiemookie
Not quite:

Quote:

According to someone who attended the semi-restricted OWASP presentation, the issue is indeed zero-day, affects all the different browsers and has nothing to do with javascript:
  • In a nutshell, it’s when you visit a malicious website and the attacker is able to take control of the links that your browser visits. The problem affects all of the different browsers except something like lynx. The issue has nothing to do with JavaScript so turning JavaScript off in your browser will not help you. It’s a fundamental flaw with the way your browser works and cannot be fixed with a simple patch. With this exploit, once you’re on the malicious web page, the bad guy can make you click on any link, any button, or anything on the page without you even seeing it happening.
http://blogs.zdnet.com/security/?p=1972
Wrong answer. With NoScript, you control what goes in and out, and this includes Flash.

-S

PS. This should help you understand:

Quote:
The NoScript Firefox extension provides extra protection for Firefox, Flock, Seamonkey and other mozilla-based browsers: this free, open source add-on allows JavaScript, Java, Flash and other plugins to be executed only by trusted web sites of your choice (e.g. your online bank), and provides the most powerful Anti-XSS protection available in a browser.
Basically, Flash or anything coming into or leaving Flash, or the browser for that matter, has to be allowed first and by default nothing is allowed. Load it already. You get to even control third party hooks into Flash. Make sense now?
__________________
SUBMAN1 is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 12:07 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright © 1995- 2025 Subsim®
"Subsim" is a registered trademark, all rights reserved.