|
|
Two weeks ago, I wrote a blog about “clickjacking,” the method of using invisible links to malicious web sites. Users click on what appear to be legitimate buttons, for example, but are actually taken to sites they can’t see. I think clickjacking will be combined with other vulnerabilities to attack users, who will be unaware that they are at risk. Protecting users from this attack vector is very important.
I have some advice for how you can protect yourselves from this new threat. For Firefox users, I suggest the latest version of the NoScript add-on for Firefox 3. You can find it here. For IE users, unfortunately, I haven’t found a patch. But I can recommend a good article that talks about clickjacking in multiple web browsers. You’ll find advice on what you can do with IE, Safari, Chrome, and Opera. Some web browsers allow users to disable the IFRAME element, but that will affect normal functions because some sites use IFRAME. You’ll need to take care if you are not using Firefox and NoScript.
|
|
Tags: clickjacking, web
Submit your own comments / message for this post