Warning: INSERT command denied to user 'dbo302458952'@'74.208.16.185' for table 'drupal_watchdog' query: INSERT INTO drupal_watchdog (uid, type, message, variables, severity, link, location, referer, hostname, timestamp) VALUES (0, 'php', '%message in %file on line %line.', 'a:4:{s:6:\"%error\";s:7:\"warning\";s:8:\"%message\";s:97:\"array_map() [<a href=\'function.array-map\'>function.array-map</a>]: Argument #2 should be an array\";s:5:\"%file\";s:70:\"/homepages/28/d101370615/htdocs/mayscript/modules/system/system.module\";s:5:\"%line\";i:1015;}', 3, '', 'http://mayscript.com/blog/david/clickjacking-attacks-unresolved', '', '54.226.213.228', 1414671046) in /homepages/28/d101370615/htdocs/mayscript/includes/database.mysql.inc on line 128

Warning: INSERT command denied to user 'dbo302458952'@'74.208.16.185' for table 'drupal_watchdog' query: INSERT INTO drupal_watchdog (uid, type, message, variables, severity, link, location, referer, hostname, timestamp) VALUES (0, 'php', '%message in %file on line %line.', 'a:4:{s:6:\"%error\";s:7:\"warning\";s:8:\"%message\";s:107:\"array_keys() [<a href=\'function.array-keys\'>function.array-keys</a>]: The first argument should be an array\";s:5:\"%file\";s:60:\"/homepages/28/d101370615/htdocs/mayscript/includes/theme.inc\";s:5:\"%line\";i:1771;}', 3, '', 'http://mayscript.com/blog/david/clickjacking-attacks-unresolved', '', '54.226.213.228', 1414671046) in /homepages/28/d101370615/htdocs/mayscript/includes/database.mysql.inc on line 128

Warning: INSERT command denied to user 'dbo302458952'@'74.208.16.185' for table 'drupal_watchdog' query: INSERT INTO drupal_watchdog (uid, type, message, variables, severity, link, location, referer, hostname, timestamp) VALUES (0, 'php', '%message in %file on line %line.', 'a:4:{s:6:\"%error\";s:7:\"warning\";s:8:\"%message\";s:39:\"Invalid argument supplied for foreach()\";s:5:\"%file\";s:60:\"/homepages/28/d101370615/htdocs/mayscript/includes/theme.inc\";s:5:\"%line\";i:1771;}', 3, '', 'http://mayscript.com/blog/david/clickjacking-attacks-unresolved', '', '54.226.213.228', 1414671046) in /homepages/28/d101370615/htdocs/mayscript/includes/database.mysql.inc on line 128
Clickjacking Attacks Unresolved | mayscript

Clickjacking Attacks Unresolved

  • warning: array_map() [function.array-map]: Argument #2 should be an array in /homepages/28/d101370615/htdocs/mayscript/modules/system/system.module on line 1015.
  • warning: array_keys() [function.array-keys]: The first argument should be an array in /homepages/28/d101370615/htdocs/mayscript/includes/theme.inc on line 1771.
  • warning: Invalid argument supplied for foreach() in /homepages/28/d101370615/htdocs/mayscript/includes/theme.inc on line 1771.

Clickjacking attacks were originally described by Robert Hansen and Jeremiah Grossman in 2008. In these attacks, the attacker tricks the user into interacting with a malicious web page, but routes the user’s input to another web page that would result in undesirable consequences. A commonly used technique is to embed the targeted web page with a completely transparent IFRAME and lure the user to click on it unintentionally. The current solution for web pages to protect themselves is using JavaScript framekillers or the browser-enforced X-Frame-Options to opt out of being framed. However, popular web applications nowadays provide widgets (or social plugins, e.g. Facebook Like buttons) that are designed to be embedded by third party websites. It should be noted that previous solutions do not offer any protection for these widgets.

We would like to share a white paper of our ongoing clickjacking research and some demos by CyLab researchers David Huang and Collin Jackson at Carnegie Mellon Silicon Valley. In our white paper, we describe a practical de-anonymization attack on social network users, based on Likejacking. We also introduce a new type of click timing attack called double-clickjacking that can bypass current defenses and steal the user’s data from popular OAuth service providers. We would like to make clear that IFRAME-based defenses are ineffective. Moreover, clickjacking is not all about IFRAMEs.

White paper: Clickjacking Attacks Unresolved