IE8's clickjacking fix not much help, security researchers say
Outsiders dispute Microsoft's claim that feature in IE8 RC1 offers 'consumer-ready' protection
IDG News Service - New technology from Microsoft Corp. designed to protect Internet Explorer users from a powerful new Web-based attack won't fix the problem, some security researchers said Tuesday.
Microsoft released the technology yesterday as part of the Release Candidate 1 version of its upcoming Internet Explorer 8 browser, saying that the feature provides "consumer-ready" protection for an attack known as clickjacking.
In clickjacking, attackers use special Web programming to trick victims into clicking Web buttons without realizing it. The attack is hard to pull off, but at its worst, clickjacking can do some very nasty things, such as execute stock trades on financial Web sites, change router or firewall configurations, or even force someone to download unwanted software.
The problem is so vast that security researchers worry that Microsoft's approach, which works only when Web site developers add special tags to their pages that prevent their own Web buttons from being misused, may end up giving IE users a false sense of security.
"It's not a solution to clickjacking by any stretch of the imagination. It's a vaguely mitigating factor for the very few people who use IE8," said Robert Hansen, CEO of SecTheory LLC, and one of the people who first reported the issue to Microsoft. "But it's interesting that they're taking it seriously."
Although some Web sites will certainly use Microsoft's technology to prevent their IE visitors from being hit with clickjacking, there are simply too many other areas in which HTML code is unlikely to be updated and hackers could launch attacks — targeting router administrative interfaces or corporate applications, for example, or going after Web sites that haven't gotten around to implementing Microsoft's fix. "This is a solution which, even if everyone decides that this is the right way to do things, it still will take years and years of education," Hansen said.
Worse, some users might mistakenly think they are protected from the attack just because they are using IE, according to Giorgio Maone, developer of the Firefox NoScript plug-in, which is widely considered the best protection from many Web-based attacks, including clickjacking.
"The bad news for IE enthusiasts is that they've got no magic 'out of the box' protection," Maone wrote in his blog Tuesday. "True, it doesn't require any 'browser add-on' ... but it comes with an even more strict requirement: All the sites to be protected must already have adopted a new proprietary hack, i.e., something no end user can verify, let alone enforce."
NoScript lets users selectively block the use of scripting languages within the Firefox browser. Because clickjacking requires scripting, the attack doesn't work when NoScript is enabled.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts