New 'Clickjacking' Threat Could Compromise Your Webcam, Interrupt Striptease. NoScript to the Rescue?
Posted 10/10/08 at 10:46:57 AM | by Paul Lilly
Those kooky hackers, what will they think of next? The latest fad sweeping the underground community involves a new type of attack (new in how it's being used, anyway) dubbed 'clickjacking,' whereby surfers click on seemingly harmless websites only to end up unknowingly forfeiting control of their webcam and microphone.
So far, clickjacking has been confirmed to affect Adobe's Flash player and for every major browser, such as Firefox, Internet Explorer, Opera, Safari, and yes, it affects Google's Chrome browser too.
"It is a very serious problem," said Giorgio Maone, author of the NoScript Firefox extension. "Clickjacking is a very simple attack to build, and now that the details are out, any script kid can try it successfully. There's no estimate to the number of trap sites."
Maone went on to warn that clickjacking is impervious to signature-based scanning. Adobe has recognized the threat as being "critical" and is instructing users on how to turn off Flash access to webcams and microphones. But is it a cure all? According to Robert Hansen, CEO of SecTheory, Flash clickjacking represents but a single variant of what could turn out to be a widespread threat, and that the only real fix will be in changing existing web standards, not the individual applications themselves.
Not all hope is lost, though, and an update to Maone's NoScript extension purports to eliminate most, if not all clickjacking attempts. NoScript 1.8.2.1 features anti-clickjacking countermeasures, the most aggressive of which is called ClearClick. The updated extension can now detect if there is a hidden, embedded element in a web page and will then display a warning. That's great for Firefox users, but no such fix exists for everyone else, at least not yet.
Anyone inclined to think twice before firing up that webcam for an intimate 'I miss you' session the next time you're away on business?

Image Credit: Flickr mofeto
Nothing new in that dept.
Submitted by mikeart03a on Fri, 2008-10-10 13:02
Webcam and Mic highjacking is nothing new these days, this probably the first one available that can target a wide audience instead of a limited segment of users (*cough* AIM *cough*). I always found it weird as to why Adobe implemented a camera function into flash... there's no real practical purpose for it. If you want to video chat, you use a Video conference app or your IM client, those are a little more secure.
- mike_art03a
IT Technician
Gov't of Canada
NoScript
Submitted by praetor_alpha on Fri, 2008-10-10 10:54
I have been using NoScript for over a year, and the amount of malware I have collected is vastly lower. Very much worth it for the occasional website that doesn't work (then tell NoScript to allow the site).
Well..
Submitted by maniacm0nk3y on Fri, 2008-10-10 10:24
Thank god I don't use a webcam. I don't see no use for one unless it's business related.
1 NEW COMMENT(S) | 29 TOTAL COMMENTS
2 NEW COMMENT(S) | 25 TOTAL COMMENTS
4 NEW COMMENT(S) | 4 TOTAL COMMENTS
4 NEW COMMENT(S) | 4 TOTAL COMMENTS









