clickjack

Mukesh Dhama ehmukeshdhama at gmail.com
Fri Nov 22 12:07:26 EST 2013


*Greetings*

I am Mukesh Dhama young security researcher from India while surfing your
website I found very serious vulnerabilities that can harm your
website reputations.


*Vulnerability #1 :-*

*Type *                     :-  ClickJacking

*Power of Bug*        :-  *High *

*Effect                     :-  Reputation of Website and Fame, Users
Cookies, Phishing through your website URL, Interruption of Contents,etc*

*Requirements       :- Firefox , JavaScript Enabled *

*URL                      :-  *http://pidgin.im





*Clickjacking, also known as a "UI redress attack", is when an attacker
uses multiple transparent or opaque layers to trick a user into clicking on
a button or link on another page when they were intending to click on the
the top level page. Thus, the attacker is "hijacking" clicks meant for
their page and routing them to other another page, most likely owned by
another application, domain, or both.Using a similar technique, keystrokes
can also be hijacked. With a carefully crafted combination of stylesheets,
iframes, and text boxes, a user can be led to believe they are typing in
the password to their email or bank account, but are instead typing into an
invisible frame controlled by the attacker.*


*I also attached coded html page for proof of concept*

*How to Fix ?*

http://javascript.info/tutorial/clickjacking

Regards---

Mukesh Dhama
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://pidgin.im/cgi-bin/mailman/private/security/attachments/20131122/6356042c/attachment.html>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://pidgin.im/cgi-bin/mailman/private/security/attachments/20131122/6356042c/attachment-0001.html>


More information about the security mailing list