-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
US-CERT Current Activity
Multiple Web Browsers Affected by Clickjacking
Original release date: September 26, 2008 at 3:28 pm
Last revised: September 26, 2008 at 3:28 pm
US-CERT is aware of public reports of a new cross-browser exploit
technique called "Clickjacking." According to one of the reports,
Clickjacking gives an attacker the ability to trick a user into
clicking on something only barely or momentarily noticeable.
Therefore, if a user clicks on a web page, they may actually be
clicking on content from another page. A separate report indicates
that this flaw affects most web browsers and that no fix is available,
but that disabling browser scripting and plug-ins may help mitigate
some of the risks.
An additional report suggests that Firefox users consider using the
NoScript plug-in as an added preventative measure. Disabling IFRAMEs
by default, as outlined in the Securing Your Web Browser document, is
reported to protect against the vulnerability.
US-CERT encourages users to review the report and follow the security
recommendations as described in the Securing Your Web Browser document
to help mitigate some of the risks.
US-CERT will provide additional information as it becomes available.
Relevant Url(s):
<http://blogs.zdnet.com/security/?p=1973>
<http://www.us-cert.gov/reading_room/securing_browser/>
<http://blogs.zdnet.com/security/?p=1972>
<http://jeremiahgrossman.blogspot.com/2008/09/cancelled-clickjacking-owasp-appsec.html>
====
This entry is available at
http://www.us-cert.gov/current/index.html#multiple_web_browsers_affected_by
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)
iQEVAwUBSN0693IHljM+H4irAQJJXAf/RvXmBtzbjk8QIar6XmN4lubBLUpkG/Zk
pYpZwKw8wnRi2KlfGFlBavGttYD1QTj8lMsc9ntEIzGe5qMy4UMtwHDxVFPR/bkK
r7qYwZnuSTGeNYNCzKl8iGb9XcxqyNiYLN3h7S1NzHG+pvqk2WlwxM2Z17pnUp1G
icDyG+ezpW4ybO4TpL5iqePYQgg7tg8ONEIsnfqSsU0Vk7BGPIscwa4Bq+n7lLB3
KChIqI/kFMduIkaf87i2un/yM46CLT9DTubmTvgePugp281FjI4ef+ODNqMmO9O/
w3mGKapkeWU7oczql/DPwRboq0WUa8moGBWIL/8nqvNbI9qi+yB/NA==
=Hn0Q
-----END PGP SIGNATURE-----