New hacking method threatens web users

Clickjacking is the newest problem presented

Updated: Wednesday, 03 Dec 2008, 6:31 PM CST
Published : Wednesday, 03 Dec 2008, 5:48 PM CST

AUSTIN (KXAN) - Clickjacking, a hacking method discovered by an Austin Internet Security Researcher, is the newest threat to internet users worldwide. "It doesn't matter if you use Internet Explorer, Firefox, Safari or any other web browser," said Internet security researcher and SecTheory CEO Robert Hansen,"They are all vulnerable."

Here is how clickjacking works:

  1. You visit a web page controlled by another person, like a blog
  2. That person can embed another web page over their blog that is invisible to you
  3. When you click on what you think is a benign link on the blog, you are actually clicking on the embedded page "So, you go click on 'submit comment' or 'next page' on the blog," explained Hansen. "But, the bad guy has actually perfectly aligned your bank account page over the blog, so you are actually clicking transfer funds or something else that gives the bad guy control over your personal information."

The examples are endless. By clicking on a tab on a seemingly harmless Web site, you could be actually accepting a friend to your MySpace or Facebook that you did not want to accept or you could be making those profiles public instead of private. To read Hansen's findings on clickjacking, visit his Web site.

SecTheory_20081203174832_JPG

SecTheory logo

Advertisement
Advertisement
Advertisement

Site Tools