Published on Maximum PC (http://www.maximumpc.com)


New 'Clickjacking' Threat Could Compromise Your Webcam, Interrupt Striptease. NoScript to the Rescue?
Created 10/10/2008 - 7:46am

Maximum IT
    • Cisco Cranks Out iPhone Security App for IT Managers
    • Verizon Puts Together Telehealth Collaboration Services
    • Ciena Coughs Up $530 Million in Cash for a Slice of Nortel Networks

    Sponsored
SEE MORE MAXIMUM IT
News
  • Google's New TiVo Ad Deal Is Good for You, Bad for Networks
  • Deals.Woot Launches, Crowdsources Thriftiness
  • Chrome Now Open for Extension Uploads
  • iPhone Responsible for Half of All Mobile Traffic, Globally
  • Amazon Boosts Kindle Battery Life, Adds Native PDF Reader
SEE MORE NEWS
News

New 'Clickjacking' Threat Could Compromise Your Webcam, Interrupt Striptease. NoScript to the Rescue?

Posted 10/10/08 at 10:46:57 AM  by Paul Lilly

comment Commentsprint Printemail EmailDeliciousDiggStumbleUponRedditFacebookSlashdot

Those kooky hackers, what will they think of next? The latest fad sweeping the underground community involves a new type of attack (new in how it's being used, anyway) dubbed 'clickjacking,' whereby surfers click on seemingly harmless websites only to end up unknowingly forfeiting control of their webcam and microphone.

So far, clickjacking has been confirmed to affect Adobe's Flash player and for every major browser, such as Firefox, Internet Explorer, Opera, Safari, and yes, it affects Google's Chrome browser too.

"It is a very serious problem," said Giorgio Maone, author of the NoScript Firefox extension. "Clickjacking is a very simple attack to build, and now that the details are out, any script kid can try it successfully. There's no estimate to the number of trap sites."

Maone went on to warn that clickjacking is impervious to signature-based scanning. Adobe has recognized the threat as being "critical" and is instructing users on how to turn off Flash access to webcams and microphones. But is it a cure all? According to Robert Hansen, CEO of SecTheory, Flash clickjacking represents but a single variant of what could turn out to be a widespread threat, and that the only real fix will be in changing existing web standards, not the individual applications themselves.

Not all hope is lost, though, and an update to Maone's NoScript extension purports to eliminate most, if not all clickjacking attempts. NoScript 1.8.2.1 features anti-clickjacking countermeasures, the most aggressive of which is called ClearClick. The updated extension can now detect if there is a hidden, embedded element in a web page and will then display a warning. That's great for Firefox users, but no such fix exists for everyone else, at least not yet.

Anyone inclined to think twice before firing up that webcam for an intimate 'I miss you' session the next time you're away on business?

Image Credit: Flickr mofeto

COMMENTS:3
TAGS: Security, webcam, hackers, clickjacking
COMMENTS
  • Login or register to post comments
  • Technology News

  • Computer Cooling Fans

  • Computer Cases

  • PC Game Controllers

  • PC Games

  • Computer Hardware

  • Headphones

  • MP3 Players

  • Stream Video

  • Computer Mouse

  • Monitors

  • Motherboards

  • NAS Storage

  • Networking

  • Laptop Computers

  • DVD Burner

  • Digital Cameras

  • Portable Storage

  • Computer Accessories

  • Smartphone

  • Antivirus Software

  • Sound Cards

  • Speakers

  • Computer Systems

  • Thumb Drives

  • Video Cameras

  • Video Card Reviews

  • Water Cooling

  • Gadgets

  • Keyboards
  • Contact Us
  • Advertising
  • Privacy Policy
  • Terms & Conditions
  • RSS Feeds
  • TechBlips
  • PCHardwareBlips
  • Site Map
  • Customer Service
Future © 2009 Future US, Inc. All Rights Reserved.

Source URL: http://www.maximumpc.com/article/news/new_clickjacking_threat_could_compromise_your_webcam_interrupt_striptease

Links:
[1] http://www.maximumpc.com/user/one4yu2c
[2] http://tech.yahoo.com/news/nf/20081008/tc_nf/62355
[3] http://www.pcworld.com/businesscenter/article/152025/firefox_extension_blocks_dangerous_web_attack.html
[4] http://www.maximumpc.com/article/internet_security_2_0
[5] http://www.maximumpc.com/article/heal_and_inoculate_your_pc
[6] http://www.maximumpc.com/article/news/mcafee_acquire_network_security_company