IE8's clickjacking fix not much help, security researchers say
Outsiders dispute Microsoft's claim that feature in IE8 RC1 offers 'consumer-ready' protection
January 27, 2009 12:00 PM ETIDG News Service - New technology from Microsoft Corp. designed to protect Internet Explorer users from a powerful new Web-based attack won't fix the problem, some security researchers said Tuesday.
Microsoft released the technology yesterday as part of the Release Candidate 1 version of its upcoming Internet Explorer 8 browser, saying that the feature provides "consumer-ready" protection for an attack known as clickjacking.
In clickjacking, attackers use special Web programming to trick victims into clicking Web buttons without realizing it. The attack is hard to pull off, but at its worst, clickjacking can do some very nasty things, such as execute stock trades on financial Web sites, change router or firewall configurations, or even force someone to download unwanted software.
The problem is so vast that security researchers worry that Microsoft's approach, which works only when Web site developers add special tags to their pages that prevent their own Web buttons from being misused, may end up giving IE users a false sense of security.
"It's not a solution to clickjacking by any stretch of the imagination. It's a vaguely mitigating factor for the very few people who use IE8," said Robert Hansen, CEO of SecTheory LLC, and one of the people who first reported the issue to Microsoft. "But it's interesting that they're taking it seriously."
Although some Web sites will certainly use Microsoft's technology to prevent their IE visitors from being hit with clickjacking, there are simply too many other areas in which HTML code is unlikely to be updated and hackers could launch attacks — targeting router administrative interfaces or corporate applications, for example, or going after Web sites that haven't gotten around to implementing Microsoft's fix. "This is a solution which, even if everyone decides that this is the right way to do things, it still will take years and years of education," Hansen said.
Worse, some users might mistakenly think they are protected from the attack just because they are using IE, according to Giorgio Maone, developer of the Firefox NoScript plug-in, which is widely considered the best protection from many Web-based attacks, including clickjacking.
"The bad news for IE enthusiasts is that they've got no magic 'out of the box' protection," Maone wrote in his blog Tuesday. "True, it doesn't require any 'browser add-on' ... but it comes with an even more strict requirement: All the sites to be protected must already have adopted a new proprietary hack, i.e., something no end user can verify, let alone enforce."
NoScript lets users selectively block the use of scripting languages within the Firefox browser. Because clickjacking requires scripting, the attack doesn't work when NoScript is enabled.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Microsoft
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Share our Strength
Download Now
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Top 10 Things to Know about Data Protection
Download Now
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...
Ponemon Study: The Business Risk of a Lost Laptop
Download Now
Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.
Airport Insecurity: The Case of Lost Laptops
Download Now
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...
