On mySimon: Michael Jackson's: This Is It
BNET Business Network:
BNET
TechRepublic
ZDNet

September 25th, 2008

Clickjacking: Researchers raise alert for scary new cross-browser exploit

Posted by Ryan Naraine @ 7:50 am

Categories: Adobe, Arbitrary Code Execution, Botnets, Browsers, Complex Attacks, Exploit code, Firefox, Flash, Google, Google Chrome, Java, Locally Running Web Servers, Malware, Microsoft, Mozilla, Patch Watch, Research, Responsible disclosure, Vulnerability research, Zero-day attacks, eBay

Tags: JavaScript, Web Browser, Web Browsers, Scripting Languages, Internet, Software/Web Development, Web Development, Ryan Naraine

Robert (RSnake) Hansen

[ UPDATE: See e-mail from NoScript creator Giorgio Maone on a possible mitigation ]

Researchers are beginning to raise an alarm for what looks like a scary new browser exploit/threat affecting all the major desktop platforms — Microsoft Internet Explorer, Mozilla Firefox, Apple Safari, Opera and Adobe Flash.

The threat, called Clickjacking, was to be discussed at the OWASP NYC AppSec 2008 Conference but, at the request of Adobe and other affected vendors, the talk was nixed until a comprehensive fix is ready.

The two researchers behind the discovery — Robert Hansen (left) and Jeremiah Grossman — have released droplets of information to highlight the severity of this issue.

So, what exactly is Clickjacking?

Clickjacking details emerge

According to someone who attended the semi-restricted OWASP presentation, the issue is indeed zero-day, affects all the different browsers and has nothing to do with JavaScript:

  • In a nutshell, it’s when you visit a malicious website and the attacker is able to take control of the links that your browser visits.  The problem affects all of the different browsers except something like lynx.  The issue has nothing to do with JavaScript so turning JavaScript off in your browser will not help you.  It’s a fundamental flaw with the way your browser works and cannot be fixed with a simple patch.  With this exploit, once you’re on the malicious web page, the bad guy can make you click on any link, any button, or anything on the page without you even seeing it happening.

[ SEE: Adobe Flash ads launching clipboard hijack attack ]

If that’s not scary enough, consider than the average end user would have no idea what’s going on during a Clickjack attack.

  • Ebay, for example, would be vulnerable to this since you could embed javascript into the web page, although, javascript is not required to exploit this.  “It makes it easier in many ways, but you do not need it.”  Use lynx to protect yourself and don’t do dynamic anything.  You can “sort of” fill out forms and things like that.  The exploit requires DHTML.  Not letting yourself be framed (framebusting code) will prevent cross-domain clickjacking, but an attacker can still force you to click any links on their page.  Each click by the user equals a clickjacking click so something like a flash game is perfect bait.

According to Hansen, the threat scenario was discussed with both Microsoft and Mozilla and they concur independently that this is a tough problem with no easy solution at the moment.

Grossman confirmed that the latest versions of Internet Explorer (including version 8) and Firefox 3 are affected.

  • In the meantime, the only fix is to disable browser scripting and plugins. We realize this doesn’t give people much technical detail to go on, but it’s the best we can do right now.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 144 Talkback(s)
Pufuttttttt........
That be some funny sheet, what dat boy up dare said. roflmfao! SOrry for de funny typing, but da hair on my palms maks it hard ta typ.... (Read the rest)
Posted by: cannibal@... Posted on: 10/30/08 You are currently: a Guest | | Terms of Use
Text or graphic  Monosdeja | 09/25/08
my web sites...  linuxoverwindows | 09/25/08
I don't understand how the clicks can hurt you.  hummingfrog | 09/25/08
Actually . . .  CobraA1 | 09/25/08
Limited User Account  Jack Fuller | 09/26/08
What this is... and isn't  brunommateus@... | 09/29/08
The problem is  AzuMao | 09/29/08
Text or graphic?  electro@... | 09/25/08
in the wild?  lars_huttar@... | 09/25/08
In the wild, not yet... maybe  electro@... | 09/25/08
Sounds like more fear mongering...  Linux User 147560 | 09/25/08
I agree  mikefarinha | 09/25/08
Lynx  ethyrdude | 09/26/08
They always leave out the affected OS  Chad_z | 09/25/08
If you would RTFA  mikefarinha | 09/25/08
@mikefarinha  Alan Smithie | 09/25/08
Chad_z has a point.  joe.smetona@... | 09/25/08
If you read closer...  _DC_ | 09/28/08
OS not same as browser  dedrizen | 09/28/08
OS Irrelevant for This Exploit  mejohnsn | 10/12/08
Did you even read the article?  LiquidLearner | 09/25/08
It doesn't require Javascript  mdemuth | 09/25/08
Sadly  LiquidLearner | 09/25/08
NoScript Mitigates Clickjacking  Giorgio Maone | 09/25/08
Thanks Giorgio  balaknair | 09/26/08
"It doesn't require Javascript" so NoScript is useless?  bmerc | 09/26/08
It affect all OSs!  electro@... | 09/25/08
Disagree  balaknair | 09/26/08
the internet is for...  linuxoverwindows | 09/25/08
Sounds like a huge problem.  monkeyman1140@... | 09/25/08
Time for some research  charley cross | 09/25/08
huh???  c00k1e | 10/08/08
Three ways to stop this exploit?  Free_Thinker | 09/25/08
From the sounds of it...  LiquidLearner | 09/25/08
D: Try Linux.  joe.smetona@... | 09/25/08
Dude, know wtf you are talking about before you reply  g2g591 | 09/27/08
Risk is Mitigated  p0figster | 10/03/08
duh....  c00k1e | 10/08/08
RE: Clickjacking: Researchers raise alert for scary new cross-browser exploit  gtvr | 09/25/08
Compromised/Hostile Banner Ads  LiquidLearner | 09/25/08
What makes lynx immune to it?  LBiege | 09/25/08
.....  Linux User 147560 | 09/25/08
So the cure is ...  LBiege | 09/25/08
Re: ....  Samic | 09/25/08
Graphics are overrated  Marcos El Malo | 09/25/08
Name the affected operating systems, please  pjotr123 | 09/25/08
Re-read The Fine Article (NT)  LBiege | 09/25/08
The "fine print" doesn't note an OS, but...  el1jones | 09/25/08
Rereading the "fine" article doesn't answer the question.  bmerc | 09/26/08
The answer to the question...  fairportfan | 09/26/08
Put your glasses on  Reged | 09/25/08
That's not a dumb question  maldain | 09/25/08
OS specific?  Me_too | 09/25/08
Didn't M$ want "full integration" of its browser into  Mahegan | 09/25/08
RE: Clickjacking: Researchers raise alert for scary new cross-browser explo  rapples | 09/25/08
Click jacking  daker | 09/25/08
Don't worry  Alan Smithie | 09/25/08
Very nice guess, but I don't think that's it.  CobraA1 | 09/25/08
Now that I think about it, you're probably right.  CobraA1 | 09/25/08
RE: Clickjacking: Researchers raise alert for scary new cross-browser explo  q1com | 09/25/08
Banners  3D0G | 09/25/08
Hijacked sites  alajon | 09/25/08
RE: Clickjacking: Researchers raise alert for scary new cross-browser exploit  algzdnet | 09/25/08
NoScript extension?  henrik@... | 09/25/08
So, that was a useless article.  cut100 | 09/25/08
Agreed  CobraA1 | 09/25/08
Click Jack  Mahegan | 09/25/08
I'm guessing...  fairportfan | 09/26/08
Possible workaround  Alan Smithie | 09/25/08
Is Chrome subject to this type of attack,  mhenriday | 09/25/08
Re: Is Chrome subject ...  strauba_z | 09/25/08
Thanks for your response, strauba_z !  mhenriday | 09/26/08
RE: Clickjacking: Researchers raise alert for scary new cross-browser exploit  linuxoverwindows | 09/25/08
SORRY  strauba_z | 09/25/08
RE: Clickjacking: Researchers raise alert for scary new cross-browser exploit  strauba_z | 09/25/08
You see it when you browse for porn  BALTHOR | 09/25/08
Pufuttttttt........  cannibal@... | 10/30/08
Firefox "NoScript" Plugin  stormbringerPA | 09/25/08
I don't think NoScript will stop this.  phatkat | 09/25/08
According to a previous post on this thread...  D. W. Bierbaum | 09/25/08
To an extent, it can  balaknair | 09/26/08
NoScript Works If You Set It Up Right  dl@... | 09/26/08
For those who have low vision or are blind, here's the text from image.  Grayson Peddie | 09/25/08
Accessibility  amlewis | 09/25/08
Firefox and NoScript  Ryan NaraineZDNet Moderator | 09/25/08
Firefox + NoScript  moralesjl15@... | 09/26/08
THIS IS NOT FEAR MONGERING  chaz15 | 09/25/08
.....  Linux User 147560 | 09/25/08
Sounds like BS  sanscartier@... | 09/25/08
Journalism or Fear Mongering?  sanscartier@... | 09/25/08
Both, and justified  AySz88 | 09/25/08
Point well taken  sanscartier@... | 09/25/08
Agree - just like the war on terror and the $700  Mahegan | 09/25/08
Right on!!  vilppuu@... | 09/26/08
Fix for Firefox?  dl@... | 09/25/08
When you click on a porn page image---  BALTHOR | 09/25/08
I found a way to implement this so called Click Jacking  zd@... | 09/26/08
RE: Clickjacking: Researchers raise alert for scary new cross-browser explo  vilppuu@... | 09/26/08
I'm very curious .....  AE4713 | 09/26/08
Because they have real journalists  sanscartier@... | 09/26/08
To some extent  AE4713 | 09/26/08
Why only ZDnet?.....  stageacter@... | 09/29/08
does anybody on the list have a clue how netsec works?  c00k1e | 10/08/08
Secure FTP ? Malicious code.  gnew18 | 09/26/08
RE: Clickjacking: Researchers raise alert for scary new cross-browser exploit  tiagara | 09/26/08
Analogy to National Enquirer is sadly true  sanscartier@... | 09/26/08
A word to the wise  The-Sensei | 09/26/08
I feel your pain  sanscartier@... | 09/26/08
Huh?  AzuMao | 09/26/08
RE: Clickjacking: Researchers raise alert for scary new cross-browser exploit  phatkat | 09/26/08
You folks crack me up  3D0G | 09/26/08
Nice theory  LegendsOfBatman | 09/26/08
Go back to work and stop thinking too far ahead ..  GetReal-mac.com | 09/27/08
That is a lame excuse for not providing information  sanscartier@... | 09/26/08
Apparently you didn't...  fairportfan | 09/26/08
The hackers have probably already figured it out  CobraA1 | 09/27/08
What's with all the commenter FUD?  ernestm@... | 09/26/08
Hate to say this, but . . .  CobraA1 | 09/27/08
Those that need it have it...  mxyzplk | 09/27/08
Thanks  Qix77 | 09/26/08
RE: Clickjacking: Researchers raise alert for scary new cross-browser exploit  Youneac | 09/26/08
Browse appliance is your best friend for now  johnf76@... | 09/26/08
RE: Clickjacking: Researchers raise alert for scary new cross-browser exploit  atari8bit@... | 09/27/08
RE: Clickjacking: Transparent gif in  keeslavin@... | 09/27/08
RE: Clickjacking: Researchers raise alert for scary new cross-browser exploit  tdunkle | 09/28/08
Why look for Clickjacking anyway?  nevergiven | 09/28/08
Outlook email in HTML  D33lite | 09/29/08
If it renders HTML  AzuMao | 09/29/08
RE: Clickjacking: Researchers raise alert for scary new cross-browser explo  bastien@... | 09/29/08
RE: Clickjacking: Researchers raise alert for scary new cross-browser exploit  Manzoni | 10/01/08
Iframe  AzuMao | 10/02/08
What Exactly is the Risk?  technology@... | 10/02/08
I'm pretty sure that  AzuMao | 10/03/08
good idea  c00k1e | 10/08/08
RE: Clickjacking: Researchers raise alert for scary new cross-browser exploit  homeschooldad@... | 10/03/08
You silly people!!  homeschooldad@... | 10/03/08
Possible theories / solutions  Allstar_z | 10/03/08
finally  c00k1e | 10/08/08
Clickjacking: SOME of you obviously haven't read the available info...  flared0ne | 10/03/08
RE: Clickjacking:a Virtual Machine is best defense  orleff | 10/10/08
Nope  AzuMao | 10/11/08
RE: mejohnsn  AzuMao | 10/13/08
RE: Clickjacking: Researchers raise alert for scary new cross-browser explo  heytherezippy | 10/14/08
no  AzuMao | 10/15/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here