GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   A browser exploit that exploits them all! (https://gfy.com/showthread.php?t=857664)

StuartD 09-26-2008 12:16 PM

A browser exploit that exploits them all!
 
http://blogs.zdnet.com/security/?p=1972&tag=nl.e589

Researchers are beginning to raise an alarm for what looks like a scary new browser exploit/threat affecting all the major desktop platforms ? Microsoft Internet Explorer, Mozilla Firefox, Apple Safari, Opera and Adobe Flash.

The threat, called Clickjacking, was to be discussed at the OWASP NYC AppSec 2008 Conference but, at the request of Adobe and other affected vendors, the talk was nixed until a comprehensive fix is ready.

mikesouth 09-26-2008 12:36 PM

can you say Zango

uno 09-26-2008 12:38 PM

know anything specific Stuey?

TheDoc 09-26-2008 12:45 PM

I think this has been going on for awhile, years..

I use click heat maps all over the place, one of them being on my warning page. I found that people kept clicking the words/text in the body that wasn't linked. Words like, Sexually Explicit, along with other very common words.

So, what I did was set a span tag on the words to split them up and changed a few words to graphics.

What I found was people quit clicking on the words. So, by simple deduction I came to the conclusion that some spyware/virus, toolbar, ect was replacing popular words on my warning pages, with links - that people would click.

Pretty much from that point I knew that some how, some way, people could steal clicks too and I would have no way of knowing it.

So hearing about this now finally means it will be corrected.

StuartD 09-26-2008 12:54 PM

Quote:

Originally Posted by uno (Post 14812491)
know anything specific Stuey?

Not a whole lot as the guys who discovered it and the companies that are aware of it are all being very tight lipped about it. But apparently it's something very inherent with how all of the browsers work so a patch won't fix it.

Here's a "guess" at what it's doing:

http://www.webadminblog.com/index.ph...psec-nyc-2008/

WiredGuy 09-26-2008 01:13 PM

Wow, seems quite serious that nobody can talk about it. I look forward to seeing what it is as it seems no fix is going to be available for some time either :)
WG


All times are GMT -7. The time now is 01:18 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123