Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

IE8's clickjacking fix not much help, security researchers say

Outsiders dispute Microsoft's claim that feature in IE8 RC1 offers 'consumer-ready' protection

January 27, 2009 12:00 PM ET

Active Comments
Anonymous says: I love that one of their arguments is that it gives IE users a false sense of security. That's essentially...
Rob says: Your analogy is wrong. The IE8 technique is broken because it *requires* cooperation by web site developers and users *cannot*...


IDG News Service - New technology from Microsoft Corp. designed to protect Internet Explorer users from a powerful new Web-based attack won't fix the problem, some security researchers said Tuesday.

Microsoft released the technology yesterday as part of the Release Candidate 1 version of its upcoming Internet Explorer 8 browser, saying that the feature provides "consumer-ready" protection for an attack known as clickjacking.

In clickjacking, attackers use special Web programming to trick victims into clicking Web buttons without realizing it. The attack is hard to pull off, but at its worst, clickjacking can do some very nasty things, such as execute stock trades on financial Web sites, change router or firewall configurations, or even force someone to download unwanted software.

The problem is so vast that security researchers worry that Microsoft's approach, which works only when Web site developers add special tags to their pages that prevent their own Web buttons from being misused, may end up giving IE users a false sense of security.

"It's not a solution to clickjacking by any stretch of the imagination. It's a vaguely mitigating factor for the very few people who use IE8," said Robert Hansen, CEO of SecTheory LLC, and one of the people who first reported the issue to Microsoft. "But it's interesting that they're taking it seriously."

Although some Web sites will certainly use Microsoft's technology to prevent their IE visitors from being hit with clickjacking, there are simply too many other areas in which HTML code is unlikely to be updated and hackers could launch attacks — targeting router administrative interfaces or corporate applications, for example, or going after Web sites that haven't gotten around to implementing Microsoft's fix. "This is a solution which, even if everyone decides that this is the right way to do things, it still will take years and years of education," Hansen said.

Worse, some users might mistakenly think they are protected from the attack just because they are using IE, according to Giorgio Maone, developer of the Firefox NoScript plug-in, which is widely considered the best protection from many Web-based attacks, including clickjacking.

"The bad news for IE enthusiasts is that they've got no magic 'out of the box' protection," Maone wrote in his blog Tuesday. "True, it doesn't require any 'browser add-on' ... but it comes with an even more strict requirement: All the sites to be protected must already have adopted a new proprietary hack, i.e., something no end user can verify, let alone enforce."

NoScript lets users selectively block the use of scripting languages within the Firefox browser. Because clickjacking requires scripting, the attack doesn't work when NoScript is enabled.


Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Jump to comments

Microsoft

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

Share our Strength
Download Now  

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...