Newsletters Welcome, Guest Log In | Register

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

0

Adobe Issues Workaround for Clickjacking Flaw

Posted by Kara Reeder Oct 9, 2008 3:06:53 PM

Although White Hat Security's Jeremiah Grossman and Robert Hansen agreed not to demonstrate a clickjacking flaw in Adobe's Flash, a proof-of-concept was still leaked. But Grossman and Hansen are among five engineers helping Adobe fix the problem, reports BetaNews.

 

This particular flaw involves a Flash page featuring a "Catch the Button" game. While users are blithely clicking on a moving target, they are actually opening up a Flash Security page that allows access to the user's Web camera.

 

The patch won't be issued until the end of October, according to PC Advisor, but Adobe has issued a workaround that recommends that users select the 'Always deny' option in Flash's Settings Manager.

Add a comment Leave a comment on this blog post.

There are no comments on this post

IT Security Manual Template

Updated for 2010 Threats!  Immediately download a customizable set of documents and templates that covers every aspect of IT Security. These templates are compliant with ISO27000, HIPAA and Sarbanes Oxley standards.

Learn more >

The IT Governance and Compliance Toolkit

This Toolkit is a collection of templates and instructional documents that help you assess and establish the crucial policies that you need to operate a secure and compliant IT organization.

Learn more >

Not All Malware Detection Is Created Equal

The Internet is now the number-one conduit for infecting users with malware. This white paper outlines the terms you need to know and the steps you should take to stay safe.

Virtual Workforce: The Key to Expanding the Business While Cutting Costs

This research report focuses on the growing trends around virtual workforces and examines three key initiatives to meet the challenges that a virtual workforce can generate.