Newsletters

Select newsletters below and click the button to sign up!

Boston News NY News
DC News Internet Daily
SiliconValley News
InternetNews Business Report




Become a Marketplace Partner



Partner With Us















Internetnews Bloggers

Recent Entries

Archives

November 2009
Sun Mon Tue Wed Thu Fri Sat
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30          

Monthly Archives

Search The Blog

Netstat -vat by Sean Michael Kerner (bio)

A command line view of IT



Twitter blocks Clickjacking attack with frame buster

twitter.jpg
From the 'Don't Click' files:

Over the span of 90 minutes today I got a whole bunch of tweets from people I follow with the message "Don't Click." Apparently it was a clickjacking attack. Clickjacking is something that involves getting the user to click on an element that then triggers a second or hidden element or action.  I've written on this topic before, which affect sall browsers even though Microsoft has a 'fix'.

According to a Twitter blog post on the subject "
"..the harm was restricted to constant reposting of the link, but we take malicious attacks on Twitter users very seriously and this morning we submitted an update which blocks this clickjacking technique."
Twitter does not provide details on what the fix is (yet at least), but it's pretty easy to see what they've done. It's a frame busting script of some sort.

Back on January 30th I wrote about clickjacking twitter and it looks like that particular exploit vector has now been mitigated with the frame buster. With a frame buster the twitter log in element itself cannot be 'broken out' of twitter such that it can be hidden on a different site in a hidden frame.

Congrats Twitter on taking action on this - a little later than you could have - but hey it's the right move.

| Comments (0) | TrackBacks (0) | Share

0 TrackBacks

Listed below are links to blogs that reference this entry: Twitter blocks Clickjacking attack with frame buster.

TrackBack URL for this entry: https://swarm.jupitermedia.com/mt-tb.cgi/7412

Leave a comment