Slashdot Mirror


Alarm Raised For "Clickjacking" Browser Exploit

Shipment Date writes "ZDNet's Zero Day blog has some new information on what looks like a scary new browser exploit/threat affecting all the major desktop platforms — Microsoft Internet Explorer, Mozilla Firefox, Apple Safari, Opera and Adobe Flash. The threat, called Clickjacking, was to be discussed at the OWASP conference but was nixed at the last minute at hte request of affected vendors. From the article: 'In a nutshell, it's when you visit a malicious website and the attacker is able to take control of the links that your browser visits. The problem affects all of the different browsers except something like lynx. The issue has nothing to do with JavaScript so turning JavaScript off in your browser will not help you.'"

32 of 308 comments (clear)

  1. Hurray for us lynx users! by Anonymous Coward · · Score: 5, Funny

    *crickets*

    1. Re:Hurray for us lynx users! by davester666 · · Score: 2, Funny

      Yes, if you use lynx, you get textjack'ed instead...

      --
      Sleep your way to a whiter smile...date a dentist!
    2. Re:Hurray for us lynx users! by Adambomb · · Score: 4, Funny

      Or Holdingdownholdingdownholdingdowncrapupupupenter-jacked.

      --
      Ice Cream has no bones.
  2. Go Lynx! by ag3ntugly · · Score: 2, Funny

    I knew there was a reason I liked lynx

    --
    i have a roll of electrical tape.
  3. The first thing I thought of by Anonymous Coward · · Score: 4, Funny

    was some weird mouse-mastubation scenario. *shudders*

    1. Re:The first thing I thought of by couchslug · · Score: 2, Funny

      "The first thing I thought of was some weird mouse-mastubation scenario."

      "Mastubation"?? I'm picturing small rodents with catheters....

      Even my capybara Lemmiwinks thinks THAT is sick.

      --
      "This post is an artistic work of fiction and falsehood. Only a fool would take anything posted here as fact."
  4. Never gonna... by null+etc. · · Score: 4, Funny

    Oh great. Expect a resurgence in rickrolls. No one can protect you!

    1. Re:Never gonna... by nine-times · · Score: 2, Funny

      With all the horrible things on the Internet, you're worried about rickrolls? Have some priorities.

      We're all going to end up seeing goatse.cx again.

    2. Re:Never gonna... by Joe+Snipe · · Score: 4, Funny

      We're all going to end up seeing goatse.cx again.
      yeah but now it will have Rick Astley playing in the background...

      --
      Sometimes, life itself is sarcasm...
    3. Re:Never gonna... by Kvasio · · Score: 2, Funny

      yeah but now it will have Rick Astley playing in the background...

      Do you mean his music or that Rick will be on "giver.jpg" this time?

    4. Re:Never gonna... by uxr · · Score: 1, Funny

      We're all going to end up seeing goatse.cx again.

      So it's just going to redirect me to my homepage?

  5. Thank Jeebus! by Anonymous Coward · · Score: 5, Funny

    Finally I have a legitimate excuse for all the pr0n sites that are in my browser history. No honey, it isn't me, it's a browsers exploit! I swear!

    1. Re:Thank Jeebus! by Roberticus · · Score: 5, Funny

      Finally I have a legitimate excuse for all the pr0n sites that are in my browser history. No honey, it isn't me, it's a browsers exploit! I swear!

      I don't know how things work for you, but saying that I just got clickjacked is only going to get me into more trouble, not less.

  6. Re:Information by eln · · Score: 5, Funny

    It's very similar to the DNS issue from a couple of months back: It's a hugely scary thing that will doom the Internet, but because we're responsible we can't tell you what it is in any detail. However, if you don't patch your browser immediately (patch not yet available), you are fucked.

    Have a nice day.

  7. didn't click by big+whiffer · · Score: 4, Funny

    i didn't even click on this story; someone must want me to read this...

  8. Re:Konqueror? by eln · · Score: 4, Funny

    The summary clearly states that only lynx is not affected. It's pretty obvious what's going on here: the exploit is a nefarious plot to make everyone switch over to lynx, thereby crippling the non-text-based porn industry.

  9. Re:Konqueror? by moderatorrater · · Score: 4, Funny

    I knew that sticking with ASCII porn would pay off someday.

  10. zomg Flash is insecure by RockMFR · · Score: 2, Funny

    Details at 11.

  11. DETAILS OF THE EXPLOIT! by Anonymous Coward · · Score: 1, Funny

    The exploit was first discovered at about 7:30 am after blogger Ryan Naraine's boss noted several "odd" adult sites appeared in mister Nariane's browser history.

    So far, the exploit seems confined to browsers on Mr. Nariane's desktop, so users of effected browsers are urged to apply all public OS/browser patches and to stay away from Ryan's desktop.

  12. Re:Information by Kaptainkid · · Score: 5, Funny

    For additional support information. Click this link. LOL

  13. Re:Information by AaxelB · · Score: 2, Funny
    And, suspicously, TFA itself is hidden behind a link! Do they really expect us to click it??

    ...I did click it. What a useless article.

    It's a fundamental flaw with the way your browser works and cannot be fixed with a simple patch.

    Oh no! There's nothing we can do!

    In the meantime, the only fix is to disable browser scripting and plugins.

    Uh... wha? I thought it didn't have to do with browser scripting and plugins?

    So it's big and scary and you can't protect against it, except by taking basic precautions to protect yourself against it. I see.

  14. Re:Information by HikingStick · · Score: 4, Funny

    You mean like the way the new Slashdot interface causes a lot of the comments to overlap, so you think you're clicking on that +3 Interesting one and you end up clicking a -1 Troll on the RNC veep candidate in a bikini...except much worse, I mean.

    --
    I use irony whenever I can, but my shirts are still wrinkled...
  15. Re:Bullshit? by Anonymous Coward · · Score: 1, Funny

    Don't trust that link!

  16. Re:Information by lysergic.acid · · Score: 5, Funny

    i still don't get it. could you give an analogy involving cars?

  17. Re:Information by Hatta · · Score: 2, Funny

    Sounds like our economy right about now.

    --
    Give me Classic Slashdot or give me death!
  18. Flashbock? by Stanistani · · Score: 2, Funny

    Is that a crisp, clean Adobe lager with a nice finish?

  19. Emergency Transfer Of Funds Required by jeff_schiller · · Score: 2, Funny

    I recommend immediately that $700B be transferred to the browser companies to fix this problem. Furthermore, we must transfer this money by end of the week with no strings attached.

  20. That's not Lynx! by Anonymous Coward · · Score: 1, Funny

    That's Google's first browser :-)

    http://googlesystem.blogspot.com/2006/03/google-browser.html

  21. Re:Konqueror? by Anonymous Coward · · Score: 1, Funny

    "sticking"

    TMI

  22. Re:Information by Cousin+Scuzzy · · Score: 5, Funny

    Better? :-P

    Well, That's better than simply turning on the radio when you needed to eject.

  23. Re:Turn to Lynx? by Anonymous Coward · · Score: 5, Funny

    I hate to burst you bubble, but it does not mean I'm 12. It means that I'm older than sin.

    You young'uns these days just don't understand anything that has a black rope coming out the back. It's got to be all "txtm3 or gtfo". 4COL. Well, @TEOTD I have a message for you, young man! GOML* and GAL! --AKAIB

    * Get Off My Lawn

  24. Re:Information by Anonymous Coward · · Score: 1, Funny

    HikingStick says: " ... and you end up clicking a -1 Troll on the RNC veep candidate in a bikini...except much worse ..."

    You mean DNC veep Joe Biden in a bikini?