Slashdot Mirror


Adobe Flash Ads Launching Clipboard Hijack Attacks

bullyBEEF writes "Malicious hackers are using booby-trapped Flash banner ads to hijack clipboards for use in rogue security software attacks. In the Web attacks, which affect Mac, Windows, and Linux users running Firefox, IE, and Safari, bad guys are seizing control of the machine's clipboard (probably using the Flash command setClipboard) and inserting a hard-to-delete URL that points to a fake anti-virus program. A number of legitimate sites have been seen to host ads carrying the attack — including Newsweek, Digg, and MSNBC.com. Researcher Aviv Raff offers a harmless demo of how it's done."

3 of 353 comments (clear)

  1. flashblock by owlnation · · Score: 5, Informative

    as though we really need yet another reason to use flashblock...

    This one small piece of technology has made browsing the web bearable again. I can't ever thank its developers enough.

  2. Re:confirmed on mac os x 10.5.4 by Mr.+Marabou+Man · · Score: 5, Informative

    Yeah ? Interesting. On my setups (Firefox 3.0.1 on Slackware & Tiger, Safari 3.1.2 on Tiger), closing the tab is sufficient to make it go away. YMMV, obviously.

  3. Lame results with Linux by keeboo · · Score: 5, Informative

    Well I accessed the page under Linux and Firefox 2 and the following things happened:

    The middle mouse button pastes as usual.
    The hijacked content only appeared with CTRL-V.

    All I need to do is to close the page tab and it's gone.

    Disappointing.