Added the Clickjacking Vulnerability blocking function in Firefox.

Source: Internet
Author: User

George Maone, an Italian security researcher who developed NoScript, a security additional component for Firefox, published the latest NoScript 1.8.2.1 last week, adding the Clickjacking protection function.
In November September this year, WhiteHat Security interserdrosman and SecTheory Robert Hansen revealed that all browsers may be affected by the Clickjacking vulnerability. They said they had discussed the vulnerability with Microsoft, Mozilla, apple, and Adobe. Adobe, however, confirmed last week that the Flash Player affected by the browser vulnerability, will allow hackers to access users' microphones and cameras. Apart from providing temporary remedial solutions, Adobe, it also promises to fix the vulnerability by the end of October.

According to Maone of the NoScript Security plug-ins in the developed Firefox browser, because this Clickjacking vulnerability comes from HTML design that allows websites to embed IFRAME content from other webpages, all browsers are spared.

Maone said that NoScript 1.8.2.1 has a new ClearClick function. When a user interacts with the webpage through a mouse or keyboard or clicks the buttons on the webpage, if these buttons or interactive components hide content from other web pages or the information is not transparent enough, a warning will be raised and the original information will be exposed. Users can use this anti-blocking browser kidnapping attack.

Currently, NoScript only supports Firefox, While IE and other browsers do not.

 

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.