On BNET: 5 classic computer pranks
BNET Business Network:
BNET
TechRepublic
ZDNet

October 7th, 2008

Adobe posts workaround for clickjacking flaw, NoScript releases ClearClick

Posted by Dancho Danchev @ 7:16 pm

Categories: Adobe, Arbitrary Code Execution, Botnets, Exploit code, Firefox, Flash, Java, Malware, Mozilla, Passwords, Patch Watch, Privacy, Web 2.0, Zero-day attacks

Tags: Security, Clickjacking, NoScript, ClearClick, Dancho Danchev

NoScript ClearClickFollowing the recent release of a PoC demonstrating clickjacking in action, Adobe has released a security advisory offering solutions for customers and IT administrators on dealing with the flaw until they releases a Flash player patch before the end of October.

“We have just posted a Security Advisory for Flash Player in response to recently published reports of a ‘Clickjacking’ issue in multiple web browsers that could allow an attacker to lure a web browser user into unknowingly clicking on a link or dialog. This potential ‘Clickjacking’ browser issue affects Adobe Flash Player’s microphone and camera access dialog. A Flash Player update to mitigate the issue will be available before the end of October. In the meantime, users can apply the workaround described in the Advisory.”

And since prevention is better than the cure — at least in the short term — the just released NoScript v1.8.2.1 aims to prove exactly the same with its ClearClick feature :

“The most specific and ambitious is called ClearClick: whenever you click or otherwise interact, through your mouse or your keyboard, with an embedded element which is partially obstructed, transparent or otherwise disguised, NoScript prevents the interaction from completing and reveals you the real thing in “clear”. At that point you can evaluate if the click target was actually the intended one, and decide if keeping it locked or unlock it for free interaction. This comes quite handy now that more dangerous usages of clickjacking are being disclosed, such as enabling your microphone or your webcam behind your back to spy you through the interwebs.”

Click in the clear, and make sure you’re not susceptible to exploitation through last quarter’s security vulnerabilities.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 9 Talkback(s)
RE: Adobe posts workaround for clickjacking flaw, NoScript releases ClearClick
I get what you're reporting but just read this sentance from the first paragraph:

"Following the recent release of a PoC demonstrating clickjacking in action, Adobe has released a security advi... (Read the rest)
Posted by: mikhey Posted on: 10/10/08  (Edited: 10/10/08 @ 11:53) You are currently: a Guest | | Terms of Use
Requires Firefox plugin  bbaston@... | 10/08/08
NoScript  riggy001@... | 10/08/08
RE: Adobe posts workaround for clickjacking flaw, NoScript releases ClearClick  michael_kassing@... | 10/08/08
I like Harvey Bardel better  zmud | 10/09/08
RE: Adobe posts workaround for clickjacking flaw, NoScript releases ClearClick  phatkat | 10/08/08
Opensource power  waltmaine | 10/08/08
Opensource power  waltmaine | 10/08/08
RE: Adobe posts workaround for clickjacking flaw, NoScript releases ClearCl  Spitduck | 10/09/08
RE: Adobe posts workaround for clickjacking flaw, NoScript releases ClearClick  mikhey | 10/10/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here