Liquid Egg Product
The Shawn Bradley of Weblogs
"Besides, being a mascot has its advantages. Like you can randomly hug cute chicks and no one's going to freak out. But you have to touch some men, too, so no one gets suspicious."
-- The Mascot

We see what you’re doing there

Oh, hey, can I scare you by telling you about a browser vulnerability you can’t do much about?

It’s been dubbed “clickjacking”, presumably because that term sounds catchy. In short, someone makes you click on something you didn’t expect. An example might be trying to click a button, but the clickjacker has created an invisible area on top of the button which is clicked instead.

Then, so reports say, the hacker might be able and willing to hijack your microphone and webcam.

How to defend yourself? At this point, you can switch to the Lynx browser (which is text-only). Disabling plug-ins (Flash, Java, etc.) and Javascript support also help. Note that both these measures cripple your web-browsing experience. (I personally am not bothering.)

And, despite the post’s title, the employees of LEP are not interested in making you a target for this attack. Considering the demographic, we’re just not that eager to sneak a peak off your webcam.

Source: Clickjacking Attack Lets Web Sites See, Hear You

October 9th, 2008 4 comments
Posted by Donnie Filed under Computer-fu