Firefox add-on blocks 'clickjacking' attacks
NoScript now stymies new class of exploits by revealing secret content
October 9, 2008 12:00 PM ETComputerworld - A popular Firefox add-on designed to block scripts and plug-ins has been updated to stymie the new "clickjacking" class of attacks, the extension's developer said today.
The latest version of NoScript, a free extension for Mozilla Corp.'s Firefox browser, now boasts something that Italian developer and security researcher Giorgio Maone calls "ClearClick" to protect users from clickjacking attacks.
"Rather than relying on frame/plug-in blocking, which were already available, I decided to move on and add a brand new feature, developed from scratch, for people who couldn't bear blocking frames outright," said Maone in an interview conducted via instant messaging.
In a blog post earlier this week, Maone spelled out what ClearClick does in greater detail. "Whenever you click or otherwise interact, through your mouse or your keyboard, with an embedded element which is partially obstructed, transparent or otherwise disguised, NoScript prevents the interaction from completing and reveals [to] you the real thing in 'clear,'" he said.
At that point, users can decide for themselves whether to continue clicking, or free up the mouse from the underlying -- and potentially exploitive -- content.
Clickjacking, which was coined just last month by a pair of American researchers -- Robert Hansen of SecTheory LLC and Jeremiah Grossman of WhiteHat Security Inc. -- describes attacks in which hackers and scammers hide under the cover of a legitimate site, then use that cover to disguise clicks. Among possible clickjacking exploits was one that Adobe Systems Inc. described this week in Flash that lets attackers secretly spy on users by getting them to turn on their computer's webcam and microphone without realizing they've done so.
"Clickjacking is bad, old and difficult to protect from because it depends Web features modern sites heavily rely upon today," said Maone. "It's also quite easy to pull [off] and unlikely to be fixed by a mainstream browser in the short term."
Although Hansen and Grossman have not yet released technical information of their clickjacking research -- they only outlined the threat in any detail yesterday -- Maone was able to create ClearClick by piecing together what clues had been made public in the last two weeks. He also got help from other researchers, including Hansen.
"Even without knowing the gory details of the [then still undisclosed] Adobe vulnerability, it was not hard analyzing the problem from a general mitigation perspective," said Maone. "[And] after I started speculating on the effectiveness of already existent NoScript features against clickjacking, notably IFRAME blocking, [Hansen] pinged me, also because he's a NoScript user himself, and we had some deeper discussion on NoScript's alternate and specific defenses."
clickjacking
Additional Resources



White Papers & Webcasts
Death to PST Files
Download Now
The Tangled Web: Silent Threats & Invisible Enemies
Download Now
Tape Killed the IT Guy
Watch Now
Forrester Consulting Mobility Study: Taking Control of Enterprise Mobile Device Diversity
Download Now
BRM: What You Can Do To Reduce Risk In Challenging Times
Watch this webcast now!
What IT Must Do to Support Employee-Owned BlackBerry, iPhone and Android Mobile Devices
Download Now
Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".
eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...

