House of Hackers

Creegan 11.9 23, Male
San José, Costa Rica

Creegan 11.9's Friends

Creegan 11.9's Groups

CR33G4N'S SHARES

Clickjacking and Flash

I heard of clickjacking a couple of weeks back when the media blast started. At that time a had a very vague idea what it was and just recently I saw some POCs coming out to show how it works in practice.

P4144556

Clickjacking, if I may categorize it, falls into the category of GUI attacks. I associate the clickjacking attack with the focus stealing attack which allows attackers to steal any file from the disk as long as they trick the victim to type enough characters. Ok, this is not a razor-sharp exploit but it is an exploit nevertheless.

In essence, the clickjacking technique allows attackers to trick the victim to click on areas of a disguised HTML elements such as an IFRAME preloaded with let’s say your Facebook account information. If nothing else, clickjacking is the killer of most anti-CSRF techniques.

I haven’t been thinking about clickjacking at all. I mean the attack is quite obvious and the potentials for damage are there. However, this morning when woke up, an interesting question started to circulate in my head. What is Adobe’s deal? After all, Adobe are the ones who asked Jeremiah and rsnake to cancel their OWASP presentation. The answer came quite quickly and naturally.

The simple truth is that Adobe are worried about the clickjacking technique because Flash’s current and even future and a lot more enhanced security model relies on user interactions, i.e. clicks performed by the user. Therefore, today attackers can trick the user to allow the microphone to survey the sound in the room where the victim’s equipment is located. They can use clickjacking for that! But there is more.

If you have been following the development of the Flash platform, you are probably aware that Flash will soon become practically the most powerful web tool out there. Seriously, Adobe are revolutionizing the way we interact with the Web. Not only Flash will support a primitive P2P streaming protocol (I need to think of something malicious to do with that…), but they will also allow users to open and save files from and to their local disk. The only catch is that this feature is available via the FileReference class which contains methods that cannot be accessed directly. Instead, the developer needs to bind them to onclick events.

IMHO I do not think that this security model is bulletproof. The potentials for abuse are obvious, and since clicks are the driving force of future Flash’s security model, then clickjacking is what it comes to mind if you want to abuse them. Perhaps, in the future we might be able to connect to TCP sockets as long as the user clicks?

In conclusion, clickjacking is not a killer problem and it does not break the web, well not entirely. However the clickjacking problem is hard to solve. IMHO, I believe that it is even harder to solve then any overflow you may have to deal with. Why? Because we are dealing with user interaction and graphic design related problems. The solution has to be so clean that it doesn’t break half of the Web.

---
gnucitizen information security gigs part of the cutting-edge network:

---
recent posts from the gnucitizen cutting-edge network:

Cards swiped under your nose
Spin Hunters is Back
Waving hand around for no reason.
Brute force WIFI with NVidia
Sing your way to online safety

Reclutas al servicio de Facebook

La próxima generación de espías del Reino Unido también depende en parte de Facebook. El servicio de inteligencia secreto británico, MI6 busca agentes dentro de la popular red social. Es habitual que esta institución busque reclutas y se promocione dentro de las universidades del país británico por lo que no resulta extraño que ahora busquen talentos dentro de Facebook, una red social muy utilizada entre los universitarios.

Venden un ordenador en eBay con los datos bancarios de varios clientes

Londres. (EFECOM).- Los datos bancarios de clientes de varios bancos han sido hallados en el disco duro de un ordenador vendido en Inglaterra en eBay, la compañía de subastas por internet. El disco contenía los números de cuentas bancarias, los de teléfonos y las firmas de más de un millón de clientes de American Express, NatWest y del Royal Bank of Scotland, informa hoy el periódico británico "The Independent".

 

Creegan's Corner

Latest Activity

Creegan 11.9 commented on the group Hackers Hispanos Oct 10
Creegan 11.9 and Z1Br4t are now friendsOct 9
Creegan 11.9 Z1Br4t
Creegan 11.9 left a comment for Crescent Hacker Oct 9
Creegan 11.9 replied to the discussion Mobile Oct 9
Creegan 11.9 left a comment for Enigma Oct 9
537465616C7468 and Creegan 11.9 are now friendsOct 8
537465616C7468 Creegan 11.9
sew_nice0999 left a comment for Creegan 11.9 Oct 8
Creegan 11.9 left a comment for sew_nice0999 Oct 8

Profile Information

Real Name:
Esteban A. Torres Hernández
Blog:
http://estebantorres.blogspot.com
Occupation:
Software Developer

Creegan 11.9's Blog

Creegan 11.9

A Social Experiment contestants

OK, here I'm going to write down the list of "enlisted" contestants for the "Social Experiment". So far we have: - Codejunky -… Continue

Posted on September 30th, 2008 at 4:00pm — 4 Comments

Creegan 11.9

HoH Administrators


As many of you have noticed, or should have, HoH has new administrators.
Basically this note is to make those administrators know by everyone, explaining a little details of everyone so each one of you knows to whom talk when the time comes.

All of us really want to make this site a better place, and also take away the script kiddies.
Also we have the goal to avoid illegal activities, to make it short, to keep the ethic rules of the site.

Continue

Posted on September 22nd, 2008 at 10:30pm — 8 Comments

Comment Wall (19 comments)

You need to be a member of House of Hackers to add comments!

Join this network

At 4:01am on October 8th, 2008, sew_nice0999 said…
did you find the video-kid with the vaccum?
At 3:24am on October 8th, 2008, sew_nice0999 said…
hey Creegan, it's called 'mad kid tosses vaccum out of window' on the video page.
Sew
At 2:56am on October 6th, 2008, glenn arrandale said…
sorry your right i do want to learn
At 2:40am on October 6th, 2008, 99876 said…
Buenos dias.
Viendo que hablas español, paso a contarte un poco la idea en este idioma.

No hay problema por de quien es la idea ni mucho menos, al contrario, no es nada nuevo que no se haya echo antes. La idea es solamente que viendo que tengo un par de pcs sin utilizar en mi piesa por el momento, se me ocurrio levantar algun tipo de servidores o algo por el estilo y jugar a tirarlos abajo, controlarlos, o esconder algun archivo en el mismo y jugar a ver quien lo consigue y lo postea en un blog de HoH.

Obviamente yo no jugaria, ya que no tiene sentido sino. Pero bueno, por lo menos para darle un poco mas de movimiento a HoH y si todo resulta bien quizas algun dia alguien mas ponga un servidor y ahi si podre jugar, sino no hay problema.

Pero bueno, con gusto ofrezco levantar los servidores para hacer un juego o si a alguien se le ocurre alguna otra idea con la que podamos utilizar estas 2 pcs, bienvenida sea.

Saludos Creegan.
At 6:12pm on September 30th, 2008, whte wolf said…
thanks creegan but really i want help
At 7:42am on September 24th, 2008, Jonah Hex said…
Creegan
What happened to PDP - is he still a administrator?
...and why has the latest blog entries been removed from the main page? This used to be the first stories I read when logging in?
At 6:15am on September 24th, 2008, Deep bLue o:) said…
Hola!!!..gracias por add .......mi espanh.......no es mui bueno....kkkkk........un saludo.......
At 11:19am on September 23rd, 2008, >>DaRkNeSsEs<< said…
primero k nada Felicitaciones x lo de Administrador, en cuanto a lo de las publicaciones, solo espero me avises donde puedo hacerlo, tambien te enviare un mensaje personal para hacerte unos comentarios adicionales, como sugerencias sobre un tema que estuve preguntando en la pagina....un saludo Creegan's, y espero estar mas en contacto contigo..
At 11:09pm on September 22nd, 2008, misunderstood said…
strange...don´t see it either
At 10:15pm on September 22nd, 2008, misunderstood said…
(gmt+1:00)
 
 

About House of Hackers

 

© 2008   Created by Petko D. (pdp) Petkov on Ning.   Create your own social network

Badges  |  Report an Issue  |  Privacy  |  Terms of Service