<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Chrome and Firefox Face Clickjacking Exploit</title>
	<atom:link href="http://www.darknet.org.uk/2009/02/chrome-and-firefox-face-clickjacking-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2009/02/chrome-and-firefox-face-clickjacking-exploit/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Sat, 21 Nov 2009 06:04:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2009/02/chrome-and-firefox-face-clickjacking-exploit/#comment-125514</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Thu, 05 Feb 2009 09:58:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1459#comment-125514</guid>
		<description>@Rafal Los: how is that a stupid solution. If security where easy we would have no compromises, no data loss, it will never be easy, things will get fixed and more issues will replace them. There is another solution, block it through the firewall, proxy and IDS, but this is only so good, and only one layer. FF + NoScript + not running programs as an admin is a good start on the client.</description>
		<content:encoded><![CDATA[<p>@Rafal Los: how is that a stupid solution. If security where easy we would have no compromises, no data loss, it will never be easy, things will get fixed and more issues will replace them. There is another solution, block it through the firewall, proxy and IDS, but this is only so good, and only one layer. FF + NoScript + not running programs as an admin is a good start on the client.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rafal Los</title>
		<link>http://www.darknet.org.uk/2009/02/chrome-and-firefox-face-clickjacking-exploit/#comment-125511</link>
		<dc:creator>Rafal Los</dc:creator>
		<pubDate>Wed, 04 Feb 2009 06:34:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1459#comment-125511</guid>
		<description>The solution is rather stupid.  FireFox + NoScript.  I can has basic security?</description>
		<content:encoded><![CDATA[<p>The solution is rather stupid.  FireFox + NoScript.  I can has basic security?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2009/02/chrome-and-firefox-face-clickjacking-exploit/#comment-125509</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Wed, 04 Feb 2009 01:55:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1459#comment-125509</guid>
		<description>@dblackshell: I didn&#039;t know what NoScripts clickjacking defence was called, hence my vagueness, but I know it is there. The dev build even implements IE8&#039;s non-standard HTTP header, I think just for giggles. 

IE8 is out, as beta and they are heavily touting its security improvements, including the http header clickjacking defence. They actaully had the gall to say they where the first browser with clickjacking defence. I know IE8&#039;s defence requires the website to have the additional header, hence why I mentioned it being a poor implementation. This same technique can be done with a framebusting header, the issue here is that IE doesn&#039;t support this standard, hence why they decided to implement their own, cause they probably couldn&#039;t get it to work.</description>
		<content:encoded><![CDATA[<p>@dblackshell: I didn&#8217;t know what NoScripts clickjacking defence was called, hence my vagueness, but I know it is there. The dev build even implements IE8&#8217;s non-standard HTTP header, I think just for giggles. </p>
<p>IE8 is out, as beta and they are heavily touting its security improvements, including the http header clickjacking defence. They actaully had the gall to say they where the first browser with clickjacking defence. I know IE8&#8217;s defence requires the website to have the additional header, hence why I mentioned it being a poor implementation. This same technique can be done with a framebusting header, the issue here is that IE doesn&#8217;t support this standard, hence why they decided to implement their own, cause they probably couldn&#8217;t get it to work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: navin</title>
		<link>http://www.darknet.org.uk/2009/02/chrome-and-firefox-face-clickjacking-exploit/#comment-125507</link>
		<dc:creator>navin</dc:creator>
		<pubDate>Tue, 03 Feb 2009 16:09:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1459#comment-125507</guid>
		<description>@ lightOS
Thanks for the links!!

@Dblackshell
Thanks for Clearclick ....might sound very n00bish, but I din&#039;t know abt it!! 

@All other n00bs like me:
Read abt Clearclick @ http://hackademix.net/2008/10/08/hello-clearclick-goodbye-clickjacking/

@ Darknet
cheers!! :)</description>
		<content:encoded><![CDATA[<p>@ lightOS<br />
Thanks for the links!!</p>
<p>@Dblackshell<br />
Thanks for Clearclick &#8230;.might sound very n00bish, but I din&#8217;t know abt it!! </p>
<p>@All other n00bs like me:<br />
Read abt Clearclick @ <a href="http://hackademix.net/2008/10/08/hello-clearclick-goodbye-clickjacking/" rel="nofollow">http://hackademix.net/2008/10/08/hello-clearclick-goodbye-clickjacking/</a></p>
<p>@ Darknet<br />
cheers!! <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dblackshell</title>
		<link>http://www.darknet.org.uk/2009/02/chrome-and-firefox-face-clickjacking-exploit/#comment-125502</link>
		<dc:creator>dblackshell</dc:creator>
		<pubDate>Tue, 03 Feb 2009 03:05:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1459#comment-125502</guid>
		<description>@Morgan Storey: the clickjacking defense in NoScripts is called ClearClick ;)

and IE8 (which even isn&#039;t out yet) isn&#039;t patched against ClickJacking, it only implements an additional HTTP reader, X-FRAME... (forgot the whole name of the header) =)</description>
		<content:encoded><![CDATA[<p>@Morgan Storey: the clickjacking defense in NoScripts is called ClearClick <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>and IE8 (which even isn&#8217;t out yet) isn&#8217;t patched against ClickJacking, it only implements an additional HTTP reader, X-FRAME&#8230; (forgot the whole name of the header) =)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2009/02/chrome-and-firefox-face-clickjacking-exploit/#comment-125501</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Mon, 02 Feb 2009 23:11:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1459#comment-125501</guid>
		<description>Oh noes clickjacking in firefox and Chrome... I really think these vulns were hyped by Microsofts IE8 department now that they have their rather badly implemented anti-clickjacking technology...

FF with no scripts built in clikcjacking defence stops this no questions asked. IE7 and even IE8 are still vulnerable to a lot of clickjacking that is done. Chrome updates without user interaction so it is probably already updated by the time I hit submit.</description>
		<content:encoded><![CDATA[<p>Oh noes clickjacking in firefox and Chrome&#8230; I really think these vulns were hyped by Microsofts IE8 department now that they have their rather badly implemented anti-clickjacking technology&#8230;</p>
<p>FF with no scripts built in clikcjacking defence stops this no questions asked. IE7 and even IE8 are still vulnerable to a lot of clickjacking that is done. Chrome updates without user interaction so it is probably already updated by the time I hit submit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LightOS</title>
		<link>http://www.darknet.org.uk/2009/02/chrome-and-firefox-face-clickjacking-exploit/#comment-125498</link>
		<dc:creator>LightOS</dc:creator>
		<pubDate>Mon, 02 Feb 2009 19:17:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1459#comment-125498</guid>
		<description>I.E. 7 is also affected, here&#039;s a PoC for each browser.

http://milw0rm.com/exploits/7912 - IE 7
http://milw0rm.com/exploits/7903 - Chrome 1.0
http://milw0rm.com/exploits/7842 - FF 3.0.5

These attacks don&#039;t always require JavaScript, they can also be accomplished with CSS.</description>
		<content:encoded><![CDATA[<p>I.E. 7 is also affected, here&#8217;s a PoC for each browser.</p>
<p><a href="http://milw0rm.com/exploits/7912" rel="nofollow">http://milw0rm.com/exploits/7912</a> &#8211; IE 7<br />
<a href="http://milw0rm.com/exploits/7903" rel="nofollow">http://milw0rm.com/exploits/7903</a> &#8211; Chrome 1.0<br />
<a href="http://milw0rm.com/exploits/7842" rel="nofollow">http://milw0rm.com/exploits/7842</a> &#8211; FF 3.0.5</p>
<p>These attacks don&#8217;t always require JavaScript, they can also be accomplished with CSS.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
