All the latest UK technology news, reviews and analysis

Security researcher warns of new clickjacking threat

by Spencer Dalziel

15 Apr 2010

Be the first to comment

  • Tweet this
Black Hat
Black Hat attendees have been shown some updated clickjacking techniques

A tool has been launched at the Black Hat security conference in Barcelona designed to highlight the increasing dangers of clickjacking, a hacking technique that fools users in to clicking on elements hidden in an iframe.

The browser-based tool was developed by security consultancy Context to " experiment with click-jacking techniques", and was introduced at the Black Hat event by Context developer Paul Stone.

Clickjacking was first seen in 2008, but was considered of limited use to hackers compared to other browser-based attacks, such as cross-site scripting and cross-site request forgery. However, Stone believes that the clickjacking threat is now much more real.

"Today's click-jacking techniques can be extended to perform powerful new attacks that can affect any web application," he said.

The new tool demonstrates the text-field injection and content extraction techniques, has a hidden mode that simulates a real clickjacking attack and lets users visualise how it works.

Stone demonstrated some updated clickjacking techniques that highlighted vulnerabilities in Internet Explorer, Firefox, Safari and Chrome.

"The tool will highlight the need for improved clickjacking defences in browsers and web applications," warned Stone.

The tool is in early beta and works best on Firefox 3.6.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

98%

0%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

c# or asp.net Software Developer

Job Specification For: Software Developer...

Project Manager for UI Development

A global Investment Bank requires a Project Manager to...

Web Developer, .Net Software Developer - ASP.Net, C#, HTML, CSS

Web Developer, .Net Software Developer - ASP.Net, C...

Verint Voice Recording Support Engineer

Verint Voice Recording Support Engineer (Verint / Nice...

To send to more than one email address, simply separate each address with a comma.