Newsletters Welcome, Guest Log In | Register

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

1

Warnings Rise About 'Clickjacking'

Posted by Susan Hall Sep 26, 2008 11:11:53 AM

Security researchers are raising the alarm about a browser exploit called "clickjacking" that affects Internet Explorer, Firefox, Safari, Opera and Adobe Flash, reports ZDNet's Ryan Naraine.

 

Adobe recently convinced researchers to cancel a talk about it scheduled for the Open Web Application Security Project conference. The researchers told Naraine that once users are lured to a malicious site, it allows the hijackers to make users click on any links on the page and without the user's knowledge.

 

While Naraine reports some patches are in the works, apparently there's no easy fix for this one.

 

Meanwhile, ZDNet's Dancho Danchev reports on a memory exhaustion denial-of-service vulnerability in Google's Chrome.

Add a comment Leave a comment on this blog post.
Sep 27, 2008 3:12 AM Guest Mike  says:

Agh! I was clickjacked into clicking this link! This has to end!!

 

 

I wonder how fast they'll get all the browser companies to change DHTML.

IT Security Manual Template

Immediately download a customizable set of documents and templates that covers every aspect of IT Security. These templates are compliant with ISO27000, HIPPAA and Sarbanes oxley standards.

Learn more >

The IT Governance and Compliance Toolkit

This Toolkit is a collection of templates and instructional documents that help you assess and establish the crucial policies that you need to operate a secure and compliant IT organization.

Learn more >

Web Security SaaS: The Next Generation of Web Security

This white paper describes the next generation of Web security and identifies the critical elements that make for lower-cost and easier-to-manage Web security solutions.

Should You Install Messaging Security Software on Your Exchange Server?

This white paper discusses the detailed results of an Osterman Research survey on messaging security software and conclusions about administrators' attitudes regarding installing third-party software on the Exchange server.

Data Loss Protection

Data-loss prevention tactics, technologies and best practices to protect your sensitive and valuable company data.

Security Information and Event Management

Best practices, strategies and technologies to help you use security information and event log management efficiently and effectively in order to get business value in terms of increased security, reduced risk, regulatory compliance and increased business agility.

Security SaaS Solutions

Hosted security solutions that not only protect your data, but reduce your security management TCO, as well.