Adobe Flash
Adobe's Flash software is vulnerable to a practice known as 'clickjacking'
R E L A T E D   C O N T E N T
ADVERTISEMENT

Adobe warns of 'clickjacking' attacks

Hackers able to fool browsers into redirection

Iain Thomson in San Francisco, vnunet.com 09 Oct 2008
ADVERTISEMENT

Adobe has issued a security alert about its Flash software that is vulnerable to a practice known as 'clickjacking'.

Clickjacking involves subverting a web page so that when a visitor clicks on a link they are redirected to a site the hacker wants them to see. It is a variant of cross-site scripting attacks but appears to be more serious.

Details of the attack were due to be published at the OWASP NYC AppSec 2008 Conference but the talk was withheld at Adobe's request until a workaround could be developed.

Jeremiah Grossman, co-founder of Whitehat Security, and one of the researchers who uncovered the technique, said in a blog posting: "Let's be clear. The responsibility of solving clickjacking does not rest solely at the feet of Adobe as there is a ton of moving parts to consider.

"Everyone including browser vendors, Adobe (plus other plug-in vendors), website owners (framebusting code) and web users (NoScript) all need their own solutions in case the others don't do enough or anything at all."

Grossman warned that almost all browsers are vulnerable because of the way they process graphics, and only text-based browsers like Lynx are secure.

The researcher has demonstrated how a hacked Flash advert could be used to take control of a computer's webcam and microphone, for example, turning it into a surveillance device.

"With clickjacking attackers can do quite a lot. Some things that could be pretty spooky. Things also performed, with a fair amount of ingenuity, quite easily," he said.

The US Computer Emergency Response Team has also issued a warning on the practice, and browser manufacturers are scrambling to come up with a method of defeating the attacks.

See also:

Sarah PalinPolitician's son in the dock  09 Oct 2008
ISSE 2008Integrated technologies the way forward, says McAfee  07 Oct 2008
Password screenMalware gets a rootkit  08 Oct 2008
ISSE 2008Reluctance to report breaches only adding to the problem  07 Oct 2008
SpamMalware-laden messages on the increase  07 Oct 2008

All Hacking
Tags: Clickjacking, Adobe, Flash, Browser, Security, Internet, Internet, Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| JAM Recruitment
Software Test Engineer 6 Weeks Contract £ 35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements ... more >
| JAM Recruitment
Software Test Engineer 3 Months Contract £35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements based ... more >
| Aston Carter
Major Investment Bank requires a Business Analyst to work within reference data IT. The reference data IT function is responsible for the three internal systems. One of the systems is a strategic repository for Client ... more >
| JAM Recruitment
Job Ref: CY - 27021979 Package: £25 – 42,000 +Bens Location: YORKSHIRE Job type: Occupational Health Position type: Permanent Hours: Full time Contact name: Mr Colin Youle Contact Company: JAM HUMAN RESOURCES Are you a ... more >
More job opportunities