<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tekblog &#187; clickjacking</title>
	<atom:link href="http://tekblog.teksquisite.com/tag/clickjacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://tekblog.teksquisite.com</link>
	<description>Tackling Technology One Byte At A Time!</description>
	<lastBuildDate>Mon, 26 Jul 2010 13:30:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>Firefox Extension Blocks Clickjacking!</title>
		<link>http://tekblog.teksquisite.com/2008/10/08/firefox-extension-blocks-clickjacking/</link>
		<comments>http://tekblog.teksquisite.com/2008/10/08/firefox-extension-blocks-clickjacking/#comments</comments>
		<pubDate>Thu, 09 Oct 2008 00:23:03 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[clickjacking]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[noscript]]></category>

		<guid isPermaLink="false">http://www.teksquisite.com/blog/?p=99</guid>
		<description><![CDATA[My concern over clickjacking (that I posted late last month on the Tekblog) appears to be resolved for safe surfing in Firefox with the upgrade of a security tool called NoScript with clearclick. BTW, I strongly believe that Firefox is one of the most secure web browsers on the internet today. Google, IBM Internet Security [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2008%2F10%2F08%2Ffirefox-extension-blocks-clickjacking%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2008%2F10%2F08%2Ffirefox-extension-blocks-clickjacking%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.teksquisite.com/blog/wp-content/uploads/2008/10/noscript-2.jpg"><img class="alignnone size-thumbnail wp-image-104" title="noscript-2" src="http://www.teksquisite.com/blog/wp-content/uploads/2008/10/noscript-2.jpg" alt="" width="150" height="150" /></a>My concern over <a title="clickjacking" href="http://www.teksquisite.com/blog/?p=69" target="_blank">clickjacking</a> (that I posted late last month on the Tekblog) appears to be resolved for safe surfing in <a title="Firefox" href="http://www.mozilla.com/en-US/firefox/" target="_blank">Firefox</a> with the upgrade of a security tool called <a href="http://noscript.net/">NoScript</a> with <a title="clearclick" href="http://hackademix.net/2008/10/08/hello-clearclick-goodbye-clickjacking/" target="_blank">clearclick</a>. BTW, I strongly believe that Firefox is one of the most secure web browsers on the internet today.</p>
<p><span id="articleBody"><em> <a href="http://www.crn.com/encyclopedia/defineterm.jhtml?term=Google&amp;x=&amp;y=">Google</a></em>, <em>IBM Internet Security Services</em>, and </span><span id="articleBody">the <em>Swiss Federal Institute of Technology </em>conducted a <a title="study" href="http://www.crn.com/security/208802248" target="_blank">study</a> &#8220;</span><span id="articleBody">Understanding the Web browser threat: Examination of vulnerable online Web browser populations and the &#8220;insecurity iceberg.&#8221; </span><span id="articleBody">The study concluded that of the hundreds of millions of users accessing Web browsers worldwide, more than 600 million were at risk of attack for not running the latest, most secure Web browser version as of June 2008. </span></p>
<p>You should check out <a title="US-CERT" href="http://www.us-cert.gov/reading_room/securing_browser/#Mozilla_Firefox" target="_blank">US-Cert</a> to read about how you can secure your web browser for safer internet surfing.  Ultimately, we must all remember that we are all responsible for contributing toward a safe internet community.  Just as you would not attempt to drive a car across country with bald tires, you should not attempt to navigate the internet with a <strong>bald browser</strong>.</p>
<p>I will admit that the NoScript addon can be a real PITA at times because you have to allow or forbid and decide what options will work best with that particular website.</p>
<p>As an example:  Clearclick blocked the home page of <a title="teksquisite" href="http://www.teksquisite.com" target="_blank"><strong>Teksquisite.com</strong></a></p>
<div id="attachment_100" class="wp-caption alignleft" style="width: 310px"><a href="http://www.teksquisite.com/blog/wp-content/uploads/2008/10/scripts-forbidden.jpg"><img class="size-medium wp-image-100" title="scripts-forbidden" src="http://www.teksquisite.com/blog/wp-content/uploads/2008/10/scripts-forbidden-300x33.jpg" alt="scripts-forbidden" width="300" height="33" /></a><p class="wp-caption-text">scripts-forbidden</p></div>
<p><a title="http://maone.net/" href="http://maone.net/" target="_blank">Giorgio Maone</a> from <a title="hackademix.net" href="http://hackademix.net/2008/10/08/hello-clearclick-goodbye-clickjacking/" target="_blank">hackademix.net</a> states that  &#8220;whenever you click or otherwise interact, through your mouse or your keyboard, with an embedded element which is partially obstructed, transparent or otherwise disguised,  <strong>NoScript</strong> prevents the interaction from completing <em>and reveals you the real thing</em> in “clear”. At that point you can evaluate if the click target was actually the intended one, and decide if keeping it locked or unlock it for free interaction.&#8221;</p>
<p>In order to allow all JavaScript menus to operate freely with clearclick I had to <em>allow teksquisite.com</em></p>
<p><em></em><a href="http://www.teksquisite.com/blog/wp-content/uploads/2008/10/allow1.jpg"><img class="alignnone size-medium wp-image-102" title="allow teksquisite.com" src="http://www.teksquisite.com/blog/wp-content/uploads/2008/10/allow1.jpg" alt="" width="264" height="263" /></a></p>
<p>You can get the latest stable version of NoScript 1.8.2.1 <a title="http://noscript.net/getit#direct" href="http://noscript.net/getit#direct" target="_blank">here</a>.   Supported browsers: Firefox 1.5.0.6 and above, SeaMonkey 1.0.5 and above, Flock, IceWeasel, and Minefield.  Don&#8217;t go on the internet without it!</p>
<p>Happy surfing <img src='http://tekblog.teksquisite.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p style="text-align: center;"><strong><a title="http://www.cgisecurity.org/2008/10/details-of-clic.html" href="http://www.cgisecurity.org/2008/10/details-of-clic.html" target="_blank">Details of Clickjacking Attack Revealed With Online Spying Demo!</a></strong></p>
<p style="text-align: left;">&#8220;A researcher has “hacked” the mysterious clickjacking attack and today posted a demonstration in his <a href="http://blog.guya.net/2008/10/07/malicious-camera-spying-using-clickjacking/" target="new">blog</a> on how the Web-borne attack works.&#8221;</p>
<p style="text-align: center;"><a title="http://www.networkworld.com/news/2008/100808-researchers-reveal-clickjacking-attack.html?page=2" href="http://www.networkworld.com/news/2008/100808-researchers-reveal-clickjacking-attack.html?page=2" target="_blank"><strong>Update on Clickjacking from Network World </strong>on 10-9-2008</a></p>
<p style="text-align: left;"><em>&#8220;For the moment, there&#8217;s little that end users can do to protect themselves and maintain the Internet&#8217;s usability, said Hansen. One tactic, only available for Firefox users, is to install the NoScript add-on, he said. &#8220;NoScript does a great job of supplementing [Mozilla's] slowness in patching, but it&#8217;s not really the best way to protect users,&#8221; Hansen said, referring to NoScript&#8217;s content blocking, which can render some sites unusable.&#8221;</em></p>
<p style="text-align: left;"><em>&#8220;Finding a solution for clickjacking will be very complicated, which is why we don&#8217;t see a quick solution,&#8221; Hansen said. &#8220;But    if we don&#8217;t give it the attention it deserves now, it could be used in the future for much more effective targeted attacks.&#8221; </em> <a href="http://www.computerworld.com/action/inform.do?command=search&amp;searchTerms=Robert+Hansen">Robert Hansen</a>, founder and CEO of SecTheory LLC</p>
<div style="float:left; margin-left:10px;">	
			<a class="LikeBotButton" />
				<script type="text/javascript">
					likebot_bgcolor = '';
					likebot_url = 'http://www.teksquisite.com/blog/?p=99';
					likebot_type = 'horizontal_thumbs';
				</script>
				<script src="http://i.likebot.com/button.js" type="text/javascript"></script>
			</a>
			
			</div>]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2008/10/08/firefox-extension-blocks-clickjacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clickjacking?</title>
		<link>http://tekblog.teksquisite.com/2008/09/29/sql-injection-via-a-cookie-that-nasty-bot/</link>
		<comments>http://tekblog.teksquisite.com/2008/09/29/sql-injection-via-a-cookie-that-nasty-bot/#comments</comments>
		<pubDate>Mon, 29 Sep 2008 15:01:22 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[clickjacking]]></category>

		<guid isPermaLink="false">http://www.teksquisite.com/blog/?p=69</guid>
		<description><![CDATA[Last Friday US-CERT warned network administrators to beware of clickjacking.  This is a fairly new threat that affects Microsoft Internet Explorer, Firefox, Safari, Opera, Chrome, and Adobe Flash.  I can honestly say that if it is anything like the iFrame exploits from last winter that haunted all of my wordpress domains,  I&#8217;ll be ripped and [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2008%2F09%2F29%2Fsql-injection-via-a-cookie-that-nasty-bot%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2008%2F09%2F29%2Fsql-injection-via-a-cookie-that-nasty-bot%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.teksquisite.com/blog/wp-content/uploads/2008/09/clicking.jpg"><img class="alignnone size-thumbnail wp-image-74" title="clicking" src="http://www.teksquisite.com/blog/wp-content/uploads/2008/09/clicking-150x150.jpg" alt="" width="150" height="150" /></a> Last Friday <a title="US-CERT" href="http://www.us-cert.gov/" target="_blank">US-CERT</a> warned network administrators to beware of clickjacking.  This is a fairly new threat that affects Microsoft Internet Explorer, Firefox, <span class="storybody"><span class="story">Safari, Opera, Chrome, and Adobe Flash.  I can honestly say that if it is anything like the iFrame exploits from last winter that haunted all of my wordpress domains,  I&#8217;ll be ripped and then ripped some more&#8230;</span></span></p>
<p><strong>Update October 07, 2008</strong></p>
<p><a title="clickjacking interview" href="http://www.cgisecurity.org/2008/10/interview-jerem.html">Interview: Jeremiah Grossman provides more details on clickjacking attack</a></p>
<div style="float:left; margin-left:10px;">	
			<a class="LikeBotButton" />
				<script type="text/javascript">
					likebot_bgcolor = '';
					likebot_url = 'http://www.teksquisite.com/blog/?p=69';
					likebot_type = 'horizontal_thumbs';
				</script>
				<script src="http://i.likebot.com/button.js" type="text/javascript"></script>
			</a>
			
			</div>]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2008/09/29/sql-injection-via-a-cookie-that-nasty-bot/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
