Newsletters Select newsletters below and click the button to sign up!
Internetnews BloggersRecent Entries
ArchivesMonthly ArchivesSearch The Blog
« New clickjacking attack for Chrome and Firefox dissected |
Sean Michael Kerner Blog
| Dell preloading Novell's SUSE Linux on thin clients »
Clickjacking Twitter is no tweetFrom the 'click here, tweet there' files: Can you Clickjack Twitter? Apparently you can. This week thanks to, Microsoft's IE 8, a followup story I did about it and a blog post yesterday I had on another clickjacking issue - this is a type of attack that is top of mind for me. With clickjacking, a user clicks on something that has a hidden element behind it that in turn triggers an unexpected action. After my post yesterday, I was made aware of some research by James Padolsey clearly showing how a Twitter clickjack can be performed. Basically what happens is when the user clicks a button an -unintended- message is tweeted. You need to be logged into the Twitter.com web interface for this 'attack' to work. If you're on Firefox, the clickjack is clearly identified by using the NoScript add-on ( click the screen shot below). There are legitimate reasons why someone would want to click from one page to post to Twitter though (without having to hide it as a clickjack that is). For example if I want you (yes you dear reader) to retweet this page: TweetThis . Don't worry in this case if you click the link you still have to click update in the Twitter web interface. Oh and hey if you want to follow me I'm here. 0 TrackBacksListed below are links to blogs that reference this entry: Clickjacking Twitter is no tweet. TrackBack URL for this entry: https://swarm.jupitermedia.com/mt-tb.cgi/6499 |
||
Leave a comment