The New Wave of Terror: Clickjacking
Home » PC Security » The New Wave of Terror: Clickjacking
By Alex | No CommentsLeave a Comment
Last updated: Thursday, May 21, 2009

Many people know that there are ways to exploit a computer. Even if a person doesn’t know how to do it they know that many hackers attack through programs. They are able to discover flaws in the programming code and find a way through it. However the new types of attacks are not only astonishing but a serious problem as well.

Clickjacking is where the hacker will set up an invisible button that is over the link that the user wants to click on. The link can be an actual link, a picture, a button, or anything else where the user would normally click. The scary part about it is that it can be on any website anywhere on the web.

Just to show how serious the problem can be there was an experiment done. The experiment showed that someone can use flash to clickjack someone. In the process the user ended up turning on their camera without even knowing it. The problem is that you may not even know that this is happening to you. It’s very possible that there are attacks that are happening that aren’t even known yet because of the discreet method that’s used.

So how does it work? Well a person that wants to clickjack someone will create what’s known as an iFrame. This will allow the internet window to be split into multiple sections allowing items to be shown in each section. The person can then insert whatever code they want and the user can’t detect it. This is because it’s hidden inside the hidden iFrame.  There’s not really a limit to what hackers can do with clickjacking and there’s no real way for consumers to protect themselves from it yet. However Internet Explorer 8 is looking promising as it will prevent the pages from being framed. However this is only for users of IE8. If you want to protect yourself then you should simply disable JavaScript.

Source: CNET

Comments

There are no comments just yet

Leave a Comment

Add your picture!
Join Gravatar and upload your avatar. C'mon, it's free!