Paving the way for .NET in Tonga
| Browse in : |
All
> Soap Box
All > Soap Box > Chaos All > Soap Box > Meanderings Any of these categories - All of these categories |
Game Over Man, Game Over ….
It looks like annoying flash has become a serious security threat.
But where does it leave the security bod out there trying to let people in their organisation use the Internet ?
Looks like a great opportunity for a security appliance border device between users and their web experience.
Net game turns PC into undercover surveillance zombie
Daniel Fleshbourne
Tue, 07 Oct 2008 18:17:02 GMT
Underscoring the severity of a new class of vulnerability known as clickjacking, a blogger has created a proof-of-concept game that uses a PC's video cam and microphone to secretly spy on the player. The demo, which is available here, appears to be a simple game that tests how quickly a user can click on a series of moving targets. Behind the scenes, it combines a generic clickjacking attack with weaknesses in Adobe's Flash technology to record the player using the PC's video camera and microphone.
The proof of concept is a powerful demonstration of the spooky implications behind clickjacking. The vulnerability allows malicious webmasters to control the links visitors click on. Once lured to a booby-trapped page, a user may think he's clicking on a link that leads to Google - when in fact it takes him to a money transfer page, a banner ad that's part of a click-fraud scheme, or any other destination the attacker chooses.View: The full story @ The Reg
Read full story...
There are no comments attached to this item.