Clickjacking vulnerability to be revealed next month
- 01 October, 2008 08:05
- Comments
After shelving plans to detail a browser clickjacking vulnerability that is indirectly related to Adobe Systems' products at the company's request earlier this month, a security researcher plans to detail the flaw next month.
Jeremiah Grossman, chief technology at White Hat Security, will discuss the vulnerability at the Hack In The Box (HITB) conference in Kuala Lumpur, Malaysia. "We have no ETA on Adobe fixes, but we're hopeful that it'll be weeks and not months. Whether or not they 'patch,' it will not change the content of my keynote speech," he wrote in an e-mail.
Grossman was scheduled to detail the clickjacking flaw with Robert Hansen, CEO of SecTheory, at the Open Web Application Security Project conference in New York, but they pulled the presentation at Adobe's request. The hackers said no pressure was put on them, but Adobe wanted time to study and address the vulnerability before it was made public. "This is not an evil 'the man is trying to keep us hackers down' situation," Hansen wrote on his blog at the time.
Clickjacking is an attack where a user clicks on a button in a browser, thinking the button will perform a specific function, such submitting a news story to Digg, but instead an attacker hijacks the button to use it for another purpose. The vulnerability is "obviously scary enough for Adobe to call it a critical issue and ask for more time, even though they were only indirectly affected," Grossman wrote in an e-mail.
Over the weekend, Grossman and Hansen planned to inform Adobe of their intent to proceed with the presentation and make the proof-of-concept code they developed available.
"We gave Adobe time out of courtesy because they asked and we have a good working relationship with them. They are using the time productively, but we could not agree to another delay," Grossman wrote. "Our belief is clickjacking as an issue is not a problem in their software, but with browsers in general. It would not be fair to the others that it does impact to be without the information they need."
HITB will be held in Kuala Lumpur from Oct. 27-30.
Come socialise with us! Facebook | LinkedIn
- Bookmark this page
- Share this article
- Got more on this story? Email ARN
- Follow ARN on twitter
- What is Wireless 2.0
- Churchtown Primary School UK Primary School Chooses Aerohive's Reliable, Manageable, Scalable and Economical Controller-less Wireless LAN Architecture
- Red Light In the Control Centre Saves Hours of Chaos
- Premier Media Group Fast Study
- Aberdeen Group: Building Business Resilience Through Active Archive
-
REVIEW: Is the Samsung Galaxy Tab 10.1 the new king of Android tablets?
-
MySpace: The next hot social network?
-
Datacom joins AFP, Microsoft and ninemsn to support ThinkUKnow
-
Lenovo awarded NSW DET netbook contract
-
Telstra-NBN Co wholesale broadband agreement “imminent”









Comments
Post new comment