<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Clickjacking and Flash</title>
	<atom:link href="http://www.gnucitizen.org/blog/clickjacking-and-flash/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/clickjacking-and-flash/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Tue, 06 Jan 2009 06:29:52 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: arborday</title>
		<link>http://www.gnucitizen.org/blog/clickjacking-and-flash/comment-page-1/#comment-124670</link>
		<dc:creator>arborday</dc:creator>
		<pubDate>Wed, 10 Dec 2008 01:08:51 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1519#comment-124670</guid>
		<description>GuardedID Toolbar for IE and Firefox says it provides clickjack protection. Can you try it out and let us know if it works? &lt;a href="http://www.guardedid.com/download.html" rel="nofollow"&gt;Test GuardedID Version 2&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>GuardedID Toolbar for IE and Firefox says it provides clickjack protection. Can you try it out and let us know if it works? <a href="http://www.guardedid.com/download.html" rel="nofollow">Test GuardedID Version 2</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: More Advanced Clickjacking - UI Redress Attacks &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/clickjacking-and-flash/comment-page-1/#comment-123962</link>
		<dc:creator>More Advanced Clickjacking - UI Redress Attacks &#124; GNUCITIZEN</dc:creator>
		<pubDate>Wed, 08 Oct 2008 18:08:34 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1519#comment-123962</guid>
		<description>[...] 2008 This will be a quick post just to share some POCs and more information regarding the recent Clickjacking technique, i.e. UI Redress Attack, a name suggested by Michael [...]</description>
		<content:encoded><![CDATA[<p>[...] 2008 This will be a quick post just to share some POCs and more information regarding the recent Clickjacking technique, i.e. UI Redress Attack, a name suggested by Michael [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/clickjacking-and-flash/comment-page-1/#comment-123958</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 08 Oct 2008 07:36:46 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1519#comment-123958</guid>
		<description>what can I say, I appreciate Georgio's work a lot but the simple fact is that NoScript can be really annoying sometimes (most of the time). Putting warnings everywhere is not the solution. I don't know what is the solution. I am glad though, that we have some solution thanks to NoScript. Clickjacking is also possible on the desktop as well. Clickjacking is certainly not a Web-related only problem. However, I do not see Desktop GUI developers implementing warnings everywhere.</description>
		<content:encoded><![CDATA[<p>what can I say, I appreciate Georgio&#8217;s work a lot but the simple fact is that NoScript can be really annoying sometimes (most of the time). Putting warnings everywhere is not the solution. I don&#8217;t know what is the solution. I am glad though, that we have some solution thanks to NoScript. Clickjacking is also possible on the desktop as well. Clickjacking is certainly not a Web-related only problem. However, I do not see Desktop GUI developers implementing warnings everywhere.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mindcorrosive</title>
		<link>http://www.gnucitizen.org/blog/clickjacking-and-flash/comment-page-1/#comment-123956</link>
		<dc:creator>mindcorrosive</dc:creator>
		<pubDate>Wed, 08 Oct 2008 05:45:01 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1519#comment-123956</guid>
		<description>It seems that something's being done to address clickjacking - NoScript's new version (1.8.2.1) sports some form of protection in this regard:

http://hackademix.net/2008/10/08/hello-clearclick-goodbye-clickjacking/

I'm not sure whether this will help against Flash clickjacking, but it certainly detected overlaid elements on a web-page and displayed a warning.</description>
		<content:encoded><![CDATA[<p>It seems that something&#8217;s being done to address clickjacking - NoScript&#8217;s new version (1.8.2.1) sports some form of protection in this regard:</p>
<p><a href="http://hackademix.net/2008/10/08/hello-clearclick-goodbye-clickjacking/" rel="nofollow">http://hackademix.net/2008/10/.....ckjacking/</a></p>
<p>I&#8217;m not sure whether this will help against Flash clickjacking, but it certainly detected overlaid elements on a web-page and displayed a warning.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Details of Clickjacking Attack Revealed With Online Spying Demo - Desktop Security News Analysis - Dark Reading</title>
		<link>http://www.gnucitizen.org/blog/clickjacking-and-flash/comment-page-1/#comment-123954</link>
		<dc:creator>Details of Clickjacking Attack Revealed With Online Spying Demo - Desktop Security News Analysis - Dark Reading</dc:creator>
		<pubDate>Tue, 07 Oct 2008 21:52:21 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1519#comment-123954</guid>
		<description>[...] term got the media's attention,? says Petko ?PDP? Petkov of GNUCitizen, who earlier this week had blogged on how clickjacking is a sort of graphical user interface attack. ?From what I can hear, other [...]</description>
		<content:encoded><![CDATA[<p>[...] term got the media&#8217;s attention,? says Petko ?PDP? Petkov of GNUCitizen, who earlier this week had blogged on how clickjacking is a sort of graphical user interface attack. ?From what I can hear, other [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ronald</title>
		<link>http://www.gnucitizen.org/blog/clickjacking-and-flash/comment-page-1/#comment-123939</link>
		<dc:creator>ronald</dc:creator>
		<pubDate>Mon, 06 Oct 2008 19:49:14 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1519#comment-123939</guid>
		<description>@arshan

it is a quite strange observation by many in the hacker &#38; security field, when people think that it must be about complexity and intellectuality. This is opposite in finding truth or even science, where the smallest theory is the most elegant generally. Whoever finds the smallest theory is usually the winner, not in hacking and security. it has to be complex that no-one understands it anymore, and you do. It's only showing inner uncertainty, instead of the confidece to talk about XSS all and and seeing it as a risk. The moment you do that you are labeled a scriptkid. Well, I always said: be affraid of the scriptkid, he will own you one day when you are far too busy with your intellectual rolegames.

This is no critique, it's my personal observation and conclusion about the fact that no one other than uncertainty will make you proof to the world you are not uncertain, which again proves de facto uncertainly.

@petko

Yeah, I think the whole notion of being the baddest and one with the most bling is ridiculous. This doesn't mean I like a healthy competion of course. But there is a thin line to walk in my opinion. A lot of bugs are being found by those in search for recognition, so in one way it's good that not many people realize it. Secondly I don't think that doing some partion magic on the TCP/IP stack is any more dangerous than clickjacking, I don't really subscribe to classifications of vulnerabilities anymore, their is either a threath or there is a good sense of security.</description>
		<content:encoded><![CDATA[<p>@arshan</p>
<p>it is a quite strange observation by many in the hacker &amp; security field, when people think that it must be about complexity and intellectuality. This is opposite in finding truth or even science, where the smallest theory is the most elegant generally. Whoever finds the smallest theory is usually the winner, not in hacking and security. it has to be complex that no-one understands it anymore, and you do. It&#8217;s only showing inner uncertainty, instead of the confidece to talk about XSS all and and seeing it as a risk. The moment you do that you are labeled a scriptkid. Well, I always said: be affraid of the scriptkid, he will own you one day when you are far too busy with your intellectual rolegames.</p>
<p>This is no critique, it&#8217;s my personal observation and conclusion about the fact that no one other than uncertainty will make you proof to the world you are not uncertain, which again proves de facto uncertainly.</p>
<p>@petko</p>
<p>Yeah, I think the whole notion of being the baddest and one with the most bling is ridiculous. This doesn&#8217;t mean I like a healthy competion of course. But there is a thin line to walk in my opinion. A lot of bugs are being found by those in search for recognition, so in one way it&#8217;s good that not many people realize it. Secondly I don&#8217;t think that doing some partion magic on the TCP/IP stack is any more dangerous than clickjacking, I don&#8217;t really subscribe to classifications of vulnerabilities anymore, their is either a threath or there is a good sense of security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/clickjacking-and-flash/comment-page-1/#comment-123933</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 06 Oct 2008 16:43:24 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1519#comment-123933</guid>
		<description>indeed, the future looks very gloomy :)

rvdh, being the baddest hacker is not enough. I know that you are the lone wolf but enter my world of massive collaboration. this is the future! well, at least according to me.</description>
		<content:encoded><![CDATA[<p>indeed, the future looks very gloomy :)</p>
<p>rvdh, being the baddest hacker is not enough. I know that you are the lone wolf but enter my world of massive collaboration. this is the future! well, at least according to me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arshan</title>
		<link>http://www.gnucitizen.org/blog/clickjacking-and-flash/comment-page-1/#comment-123932</link>
		<dc:creator>arshan</dc:creator>
		<pubDate>Mon, 06 Oct 2008 15:55:41 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1519#comment-123932</guid>
		<description>Ronald, you are right and I think that's what we both meant (about using Clickjacking to trick the user into clicking 'Allow' in the Flash security dialog).</description>
		<content:encoded><![CDATA[<p>Ronald, you are right and I think that&#8217;s what we both meant (about using Clickjacking to trick the user into clicking &#8216;Allow&#8217; in the Flash security dialog).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arshan</title>
		<link>http://www.gnucitizen.org/blog/clickjacking-and-flash/comment-page-1/#comment-123931</link>
		<dc:creator>arshan</dc:creator>
		<pubDate>Mon, 06 Oct 2008 14:32:48 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1519#comment-123931</guid>
		<description>&lt;blockquote&gt;Therefore, today attackers can trick the user to allow the microphone to survey the sound in the room where the victim’s equipment is located.&lt;/blockquote&gt;

This is the vector I came up with right away after understanding the whole Clickjacking idea, and I resisted the urge to 0day Adobe on stage in NYC - it was tough, especially with the whole crowd salivating for vectors.

There are worse vectors though, even within Flash. This is a real creative challenge to those willing to spend the time researching.

The future is scary- just check out HTML5, google, and check out some of the streaming options our browsers are looking into implementing.</description>
		<content:encoded><![CDATA[<blockquote><p>Therefore, today attackers can trick the user to allow the microphone to survey the sound in the room where the victim’s equipment is located.</p></blockquote>
<p>This is the vector I came up with right away after understanding the whole Clickjacking idea, and I resisted the urge to 0day Adobe on stage in NYC - it was tough, especially with the whole crowd salivating for vectors.</p>
<p>There are worse vectors though, even within Flash. This is a real creative challenge to those willing to spend the time researching.</p>
<p>The future is scary- just check out HTML5, google, and check out some of the streaming options our browsers are looking into implementing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rvdh</title>
		<link>http://www.gnucitizen.org/blog/clickjacking-and-flash/comment-page-1/#comment-123929</link>
		<dc:creator>rvdh</dc:creator>
		<pubDate>Mon, 06 Oct 2008 11:04:32 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1519#comment-123929</guid>
		<description>It's probably more like enabling the cam and mic access through flash. Ever seen that little popup when clicking on flash? That's another thing you can do. besides clicking on buttons and stuff. mere guess of course, and some also e-mailed me about this as an attack vector.

But I'm not sure, we'll have to wait for the stuff to roll right I guess. I'm a bit agitated by semi-disclosure right now, the media twist things out of perspective lately without doing research an taking stuff on face value. Even when I speak about something, I always ask them nicely to NOT address me as security researcher since I have no authority to claim such, other than being a semi-bored blogger that likes to go an the bend once in a while, but they don't seem to care, it sells more ads for them :)

Not sure what is happening lately, all strange things happening all over the place, old TCP attacks, weird click attacks, old purged DNS attacks dis-covered, BGP attacks, haha! no disrespect but it's just a crazy observation where you are pretty much spot on when you said that it's not about being the baddest hacker. 

I would love to tell bad-ass stories, but I know I can't because people know my name. Crazy I know, funny: hell yeah.</description>
		<content:encoded><![CDATA[<p>It&#8217;s probably more like enabling the cam and mic access through flash. Ever seen that little popup when clicking on flash? That&#8217;s another thing you can do. besides clicking on buttons and stuff. mere guess of course, and some also e-mailed me about this as an attack vector.</p>
<p>But I&#8217;m not sure, we&#8217;ll have to wait for the stuff to roll right I guess. I&#8217;m a bit agitated by semi-disclosure right now, the media twist things out of perspective lately without doing research an taking stuff on face value. Even when I speak about something, I always ask them nicely to NOT address me as security researcher since I have no authority to claim such, other than being a semi-bored blogger that likes to go an the bend once in a while, but they don&#8217;t seem to care, it sells more ads for them :)</p>
<p>Not sure what is happening lately, all strange things happening all over the place, old TCP attacks, weird click attacks, old purged DNS attacks dis-covered, BGP attacks, haha! no disrespect but it&#8217;s just a crazy observation where you are pretty much spot on when you said that it&#8217;s not about being the baddest hacker. </p>
<p>I would love to tell bad-ass stories, but I know I can&#8217;t because people know my name. Crazy I know, funny: hell yeah.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
