Clickjacking - Getting Tricked into Clicking on Invisible URLs   - 1,067 Views, 1 Comment

Summary: Click jacking is a malicious practice in which the bad guys essentially lay an invisible web page on top of the page that the user sees, so that when the user clicks a button or link, they are really performing the action of the invisible link that is overlayed on top of the button or link they believe that they are clicking (hence the term "click jack"). Often that invisible link is structured to grab their confidential information, such as a username and password.

Previous Article « Satellites Crash Over Russia, Disrupt Portable Sat Phone Communications
Read Next Article » Get and Send Great St Valentines Day Gift Baskets - All Online! You Can Even Paypal Valentines Gifts and Baskets!

  Follow Anne on Twitter     Friend Anne on Facebook

Clickjacking is a malicious practice in which the bad guys essentially lay an invisible web page on top of the page that the user sees, so that when the user clicks a button or link, they are really performing the action of the invisible link that is overlayed on top of the button or link they believe that they are clicking (hence the term “clickjack”). Often that invisible link is structured to grab their confidential information, such as a username and password.

According to the United States Computer Emergency Readiness Team (U.S. CERT), “Clickjacking gives an attacker the ability to trick a user into clicking on something only barely or momentarily noticeable. Therefore, if users click on a Web page, they may actually be clicking on content from another page.”

For example, the user on the clickjacked site may believe that they are clicking on a link or button to “See a cute kitten”, but in reality they are clicking on an invisible link that is hidden on top of the cute kitten link, and that will take them to Hotmail, and if they have a Hotmail account - and their password is stored in their browser as a cookie or other stored value - the bad guys now have their Hotmail account information - including the password.

Clickjacking works by taking advantage of certain “features” (vulnerabilities) in a large number of widely-deployed and popular browsers. While the industry scrambles to address the situation, users who are using Firefox can get some protection by using the Firefox “NoScript” add-on, which is available here.

Have you been clickjacked? Tell us about it below.

Clickjacking - Getting Tricked into Clicking on Invisible URLs

 Follow Anne on Twitter

 Twitter Explained in Plain English

 Friend Anne on Facebook

Previous Article « Satellites Crash Over Russia, Disrupt Portable Sat Phone Communications
Read Next Article » Get and Send Great St Valentines Day Gift Baskets - All Online! You Can Even Paypal Valentines Gifts and Baskets!

Read more:

»  Spammers Use Google URLs in Spam to Trick People

»  Make Email Addresses on Websites Invisible to Scrapers and Harvesters!

»  Spammers Turn to Short URL Services to Cloak Spammed Sites URLs

»  Phishers Use Wildcard DNS to Build Convincing Bait URLs - Spamfo

For additional similar stories check out our archives on Everything Else

NOTE: We never, ever, ever will recommend any product or service on this site that we have not regularly used ourselves and do not wholeheartedly believe in. That said, in some cases after being very pleased with a product or service, we may enter into a relationship with the provider of that product or service such that if someone purchases that product or service based on our recommendation, we may get a small payment. Such payments go towards the upkeep of the Internet Patrol.

 

1 Comment »

  1. Thanks for your informative article.
    I immediately added the noscript extension to Firefox. And, I’m now looking at this page with the noscript options bar across the bottom of my browser. I think I’ll just let the extension operate with its default settings. But, I’d be very interested if you or one of the commenters would recommend an article for general or practical use of noscript.

    Comment by Dbob — 2/13/2009 @ 8:42 am

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
 This article first appeared on 2/12/2009
The Internet Patrol
Patrolling the Internet for You!