Clickjacking Twitter

Clickjacking is a technique that's sometimes used by various internet nasties to get users to unwittingly click on something they didn't intend to. Javascript is used to carefully position an invisible frame under the mouse pointer. When the user attempts to click on something visible on the page, the click is transmitted to the contents of the invisible frame instead.

This has been used in the past to trick a user into clicking through a Flash security dialog, allowing the site owner to secretly access a user's web cam and microphone. A patch was issued for Flash that doesn't allow the camera to be accessed in certain scenarios, but as James Padolsey illustrates with a Twitter Clickjack attack, there are numerous other ways for this trick to be used to fool a user.

Using the basic technique of positioning an iframe over a button coupled with Twitter's 'status' URL parameter I have created a small demo which shows you just how serious (and annoying) this could be!

...

What does this mean? It means anyone can update your Twitter status without you knowing! Actually, it's YOU that's updating it, you just don't know at the time.

This is a pretty harmless example but I can imagine it being used for more sinister endeavours!

If you're a Firefox user, there's a browser addon called NoScript which can protect you from these sort of attacks. Besides allowing you to control which sites are allowed to execute Javascript, Flash, and Java, it also has a built-in tool called clearClick which compares any page you view in its unaltered form and with all of its iFrame's opacity set to 100%. If there are differences, it gives you a warning that there may be a Clickjack attempt present.


Clickjacking Twitter
NoScript


Recent Entries

Comments

Oldest comments listed first.

Posted by: Nathaniel on January 30, 2009 at 4:38 AM

I use NoScript, and while it took a little patience to get used to, I think it is the most essential tool that I have added to Firefox.


Leave a comment


Subscribe to MAKE!Subscribe to MAKE Magazine!

Subscribe today, save 42% and get web access to MAKE free. MAKE Digital Edition is available only to subscribers.

$34.95 / 1 year
(4 Quarterly Issues)

Subscribe now


Void your warranty, violate a user agreement, fry a circuit, blow a fuse, poke an eye out. Make: The risk-takers, the doers, the makers of things... Welcome to Make: Online!


CRAFT Maker Shed Maker Faire MAKE television
Holiday Gift Guides from MAKE
Gifts for Dads
Science and Chemistry
Gifts Under $20
More guides: Santa Claus Machines, Geek Toys for Grown Up Girls & Boys


Check out all of the episodes of Make: television

Alex Rider Dream Gadget Contest
Make: Science Room

Connect with MAKE

Be a MAKE fan on Facebook MAKE on Facebook
Visit our Facebook page and become a fan of MAKE!
MAKE on Twitter MAKE on Twitter
Follow our MAKE tweets!
MAKE Flickr Pool MAKE on Flickr
Join our MAKE Flickr Pool!
    make_tips on Twitter




    Maker SHED

    Advertise here with FM.

    Why advertise on MAKE?
    Read what folks are saying about us!

    Click here to advertise on MAKE!



    Subscribe to MAKE Magazine!

    Make: Online authors!

    Gareth BranwynGareth Branwyn
    Senior Editor


    Phillip TorronePhillip Torrone
    Senior Editor
    | AIM | Twitter


    Becky SternBecky Stern
    Associate Editor
    | AIM | Twitter


    Marc de VinckMarc de Vinck
    Contributing Writer
    | AIM | Twitter


    John ParkJohn Park
    Contributing Writer
    | Twitter


    Sean RaganSean Ragan
    Contributing Writer
    | Twitter


    Matt MetsMatt Mets
    Contributing Writer
    | AIM | Twitter


    Dale DoughertyDale Dougherty
    Editor & Publisher
    | Twitter


    Shawn ConnallyShawn Connally
    Managing Editor
    | Twitter


    Goli MohammadiGoli Mohammadi
    Associate Managing Editor

    Kip KayKip Kay
    Weekend Projects
    | AIM | Twitter


    Collin CunninghamCollin Cunningham
    Contributing Writer
    | AIM | Twitter

    Adam FlahertyAdam Flaherty
    Contributing Writer
    | AIM | Twitter



    More contributors: Mark Frauenfelder (Editor-in-Chief, MAKE magazine), Kipp Bradford (Technical Consultant/Writer), Chris Connors (Education), Diana Eng (Guest Author), Peter Horvath (Intern), Brian Jepson (O'Reilly Media), Robert Bruce Thompson (Science Room)

    Suggest a Site!

    Current Podcast

    itunesdl.gif Weekend Project: Beetlebot Simple robot from your parts bin that avoids obstacles. Thanks go to Jerome Demers for the original article in MAKE, Volume 12. To download the Beetlebot video, click here or subscribe in iTunes. Check out the complete Beetlebot article... More...

    Get the Make: Online sent via email
    Enter your email to receive Make: Online each day:



    MAKE Fascination video series brought to you by Dow

    Make: Education
    MAKE: en EspaƱol MAKE: Japan
    Important please read


    Subscribe to MAKE Magazine!

    Recent Posts from the Craft: Blog