Clickjacking
Posted by: ndebord
Date: January 30, 2009 03:57AM

Anybody know if this clickjacking flaw also hits K-Meleon, along with Chrome and FF?

http://news.zdnet.com/2100-9595_22-264761.html

N

Re: Clickjacking
Posted by: Fred
Date: January 30, 2009 08:18AM

It may very well be that K-Meleon is vulnerable to
clickjacking. Only disabling Javascript can make you
more or less secure. Using NoScript may help also,
but this is not yet ascertained.
Some details here :

http://www.heise-online.co.uk/news/Popular-browsers-continue-to-be-vulnerable-to-clickjacking-attacks-Updated--/112518

Fred

Re: Clickjacking
Posted by: guenter
Date: January 31, 2009 02:12AM


Finally leads to a POC that uses onClick to substitute an URL, silly.

Fred's links ends with the comment of the NoScript dev.

p.s. Eyes-Only once said that it is up to the user to do dangerous things.

BTW.I go to my bank. Close my browser - then restart 2 I go downtown or... for...- like in real life.

My banker recommended it - :O



Edited 2 time(s). Last edit at 01/31/2009 02:17AM by guenter.

Re: Clickjacking
Posted by: ndebord
Date: January 31, 2009 02:51AM

Fred,

My custom is to use Privacy Bar with Java and Javascript turned off unless it is a site I must use. So there is some comfort there. I wondered about how NoScript would handle new sites, which is the most likely place where problems would occur, so a list would not work?

N

Re: Clickjacking
Posted by: Fred
Date: January 31, 2009 04:54AM

If you have whitelist containing only a few sites
that you believe to be trustworthy (or better, that
you think are watched closely and frequently by the
responsable webmaster), and give permissions to no
other site, you should be rather safe, but if you allow
scripting each time when you get stuck without javascript,
it depends on the anti-clickjacking power of NoScript,
which I cannot yet judge, how safe you are.
As Guenter said, it is advisable to clean cache and
history, close down and restart the browser before
doing an important action.
There may still be the possibility, that a bank site
has been changed, but then you could hold them
responsible for your damages.

Fred

Re: Clickjacking
Posted by: caktus
Date: February 02, 2009 02:08PM

Might there be a way to type the url or click on a link with out it using the cache since clearing the cache each time is somewhat impractical?

Charlie

~~If it ain't broke, why screw it up?~~


Re: Clickjacking
Posted by: desga2
Date: February 02, 2009 04:36PM

You can disable cache.

K-Meleon in Spanish

Re: Clickjacking
Posted by: disrupted
Date: February 02, 2009 08:27PM

you can also use privacy mode profile:
http://kmeleonbrowser.org/forum/read.php?1,83391

Re: Clickjacking
Posted by: JamesD
Date: February 02, 2009 11:07PM

Quote
caktus
Might there be a way to type the url or click on a link with out it using the cache since clearing the cache each time is somewhat impractical?

Maybe use this CommandID in some way.

ID_NAV_FORCE_RELOAD
Reload current page without cache query.

K-Meleon forum is powered by Phorum.