October 8, 2008
3:41 am | Last updated: October 8, 2008 at: 4:39 am

A blogger has created a proof-of-concept game (based on clickjacking vulnerability) — that uses a PC's video cam and microphone to secretly spy on the player. The demo appears to be a simple game that tests how quickly a user can click on a series of moving targets. Behind the scenes, it combines a generic clickjacking attack with weaknesses in Adobe's Flash technology to record the player using the PC's video camera and microphone.

The proof of concept is a powerful demonstration of the spooky implications behind clickjacking. The vulnerability allows malicious webmasters to control the links visitors click on. Once lured to a booby-trapped page, a user may think he's clicking on a link that leads to Google - when in fact it takes him to a money transfer page, a banner ad that's part of a click-fraud scheme, or any other destination the attacker chooses.

Full Article

Loading

Contextual Related Posts:

No followup yet

Leave a Response

Comment Preview
« Yahoo Calendar Beta: A calendar service released in U.S., India, Brazil, TaiwanTouchType for iPhone: Makes email better with landscape mode »
Feed Icon

Subscribe via RSS or email: