Firefox does its bit to fight Clickjacking Attacks.

Mozilla the open-source company as always has done its bit in providing users with the safest way to surf the internet. Mozilla is offering a new plug-in that would for the Firefox Browser that blocks clickjacking which security researchers are calling on of the dangerous problem on the Web.

Clickjacking occurs when a user a user accidently clicks on a invisible link which leads the person to a malicious site without their knowledge. This is possible due to the design feature in HTML which lets websites embed content from other sites. This means that every website is vulnerable.

mousegest Firefox does its bit to fight Clickjacking Attacks.

The Firefox add-on NoScript is a very well known security Plug-in which is used to block all types of content in a webpage. However it is not a security scanner as it does not scan content with reference to a specific signature database to search for specific threats. It is a tool to block certain type of content. Firefox now comes with a added feature in this plug-in called ClearClick to fight Clickjacking.

Clickjacking is also known as user-interface redress attacks which should be blocked by NoScript plug-in, however there are a few downsides for the same.

But again the plug-in can only save users who have Firefox, the rest 70% who use other browsers are still at risk.

To combat clickjacking other browsers will come up with a fix soon. The only thing is that Mozilla realized the dangers and the others are still not concerned about the same.

However clickjacking is just not limited to websites, it can also be harmful for applications. A Live example of clickjacking was when a concept called “the clicking game” where people were told to click on a link on the right places to reconfigure the settings for the security for their webcams and microphone and in turn the victims gave access to their webcams and microphones.

More insights into Clickjacking:

In clickjacking, iframes and web page layers are used in DHTML in such as way that illegitimate buttons are overlaid on the existing legitimate buttons. The user when comes to a particular website thinks that he or she is clicking on a genuine link but they are instead clicking on something that’s harmful.

mouse Firefox does its bit to fight Clickjacking Attacks.

It really an interesting thing actually as very little is known about it and that leads to no tools to detect if a particular website is affected. We also don’t know how widespread clickjacking is. To develop a tool for the same what we need is more incidents where people are affected to study and find all the things that are possible with clickjacking. But the only problem with that is that by the time we learn all that it is too late and it has done all the harm that it could do. It’s just like installing a burglar alarm after the burglar has cleaned up your house.

How to disable Clickjacking?

The best way is to disable Flash. In Firefox however you have the plug-in now to protect you but you also have the option of extension called Flashblock which disables Flash scripts. It leaves a blank placeholder where you had a flash script which can be enabled by clicking on it. For Microsoft Internet Explorer you have to make changes in the Windows Registry.

Posted under Network and Security

This post was written by Brad on October 16, 2008

Tags: browser safety, Clickjacking, firefox, Mozilla, user-interface redress attacks

Now find your location using Firefox Geode.

Mozilla the makers of Firefox has released a new service “Geode” which will help users locate the physical location of computers.

The Geode is an experiment before the launch of its complete Geo-location tool with the launch of verion 3.1

goede Now find your location using Firefox Geode.

The Geode tool will be completely controlled by the users. Users will have option to provide how much information they give.

The technology used is from a firm called Skyhook which works out a computer’s location from nearby wireless networks.

The system can pinpoint the location within the accuracy of 10 to 20 metres within seconds using a so called system Loki.

The toll might be used for more than finding the location of a new restaurant. It will adda new dimension to the way people search for locations.

When a website requests for a location, a notification bar will alert the user and the user can decide  whether to give the exact location.

Yahoo Fire eagle will also use Geode for a number of location-aware applications.

Mr Shaver said that “That’s one of the reasons why we want people to try out Geode. We want people to tell us about their experiences and we realise it could become irksome, for example if every website is asking you whether you want to reveal your location”

Posted under Latest News

This post was written by Brad on October 11, 2008

Tags: firefox, Firefox Geode, Geode, Mozilla, Mozilla Geode