PDA

View Full Version : clickjacking unpatched since 2002


davidh
October 6th, 2008, 05:41 AM
ClickJacking as an attack technique Robert and I discovered around a year and a half ago. Recently we're told we’ve been told that its been known by the browser vendors since 2002. In any case the attack has been essentially underestimated and largely undefended by the web security community in general.http://www.cgisecurity.org/2008/10/interview-jerem.html

Such long "overexposure" (six years) may be telling that it's REALLY HARD to fix the problem :(
DH

Not necessarily related to this post, but, I am MOL disgusted by the fact that so many web sites are IMPOSSIBLE to merely navigate without enabling Javascript and/or Flash :(:confused::mad::p:o:rolleyes::eek: