DV Hardware bringing you the hottest news about processors, graphics cards, Intel, AMD, NVIDIA, ATi, hardware and technology!

   Home | News submit | News Archives | Reviews | Articles | Howto's | Advertise
 
DarkVision Hardware - Daily tech news
  Login/sign up  


Main Menu

Home
User account
Info
News archives
Links
Articles
Howto
Reviews
Member list
 

Who's Online
There are currently 117 people and 0 DV-member(s) online.

 

Latest Reviews
  • Enermax Aeolus Premium CP003
  • Altego Clear Laptop Sleeve
  • Lian Li PC-V354
  • Arctic Cooling K381 keyboard
  • Arctic Power Charger Plus
  • ATP PhotoFinder Mini
  • BitFenix Colossus
  • Roccat Taito Kingsize mTw Edition mousepad
  •  

    RSS
    RSS
     

    Google Chrome and Firefox exposed to clickjacking

    Posted on Friday, January 30 2009 @ 07:20:20 CET by Thomas De Maesschalck


    Security researchers discovered a "clickjacking" flaw that impacts both Google Chrome and Firefox, it enables an attacker to hijack a browser's functions by substituting a legitimate link with one of the attacker's choice.
    "Attackers can trick users into performing actions which the users never intended to do and there is no way of tracing such actions later, as the user was genuinely authenticated on the other page," Sood said within the disclosure.

    While Google is working on a fix, a representative for the Australian arm of the company pointed out that clickjacking can affect all browsers, not just Chrome.

    "The (clickjacking) issue is tied to the way the Web and Web pages were designed to work, and there is no simple fix for any particular browser. We are working with other stakeholders to come up with a standardized long-term mitigation approach," they said.

    However, Nishad Herath, an independent security researcher and CEO of Australian security consultancy Novologica, told ZDNet.com.au that after running Sood's proof of concept he found that Internet Explorer 8 (release candidate 1 and beta 2 versions) and Opera 9.63 (the latest version) were not exposed to the flaw. But, like Chrome, Firefox 3.0.5 was exposed.
    More info at CNET.


     
    Threshold
      
    The comments are owned by the poster. We aren't responsible for their content.
     

    DV Hardware - Privacy statement
    All logos and trademarks are property of their respective owner.
    The comments are property of their posters, all the rest © 2002-2012 DM Media Group bvba