Clickjacking on Humble (Recaptcha)

Ask for help about NoScript, no registration needed to post
Brosh

Clickjacking on Humble (Recaptcha)

Post by Brosh »

Hello there.

Was just about to log in to Humble Bundle (https://www.humblebundle.com/) when I noticed a captcha, I assume it's because I had an old password saved in the browser and it tried to auto-login with that first. When I clicked on the "I'm not a robot" part however, it generates a clearclick warning.

I'm sure it's something innocent as hovering between the two images gives the same sort of result, just a few pixels higher, and the captcha appears in the existing frame so I thought maybe that was causing it. Still I figured it was worth asking if it's ok to allow.

The report ID was 643075.

Thanks!
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:49.0) Gecko/20100101 Firefox/49.0
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: Clickjacking on Humble (Recaptcha)

Post by Thrawn »

If the 'before' and 'after' images both look like what you intend to click on, then yes, it's safe.
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:45.0) Gecko/20100101 Firefox/45.0
Brosh

Re: Clickjacking on Humble (Recaptcha)

Post by Brosh »

Aha ok.

Thank you very much.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:49.0) Gecko/20100101 Firefox/49.0
Guest

Re: Clickjacking on Humble (Recaptcha)

Post by Guest »

I get a clickjack warning when clicking the embedded Captcha on paket.de, surely safe but same as described in ticket https://trac.torproject.org/projects/tor/ticket/14985. (Win 10 Pro 64-bit, FF and Noscript each current version).
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:50.0) Gecko/20100101 Firefox/50.0
barbaz
Senior Member
Posts: 11141
Joined: Sat Aug 03, 2013 5:45 pm

Re: Clickjacking on Humble (Recaptcha)

Post by barbaz »

Report ID?
*Always* check the changelogs BEFORE updating that important software!
-
Guest

Re: Clickjacking on Humble (Recaptcha)

Post by Guest »

Sorry, I don't know. Left the browser open for hours and just logged in again and it was working ... I'll make sure to note the report id if it happens again. Thank you.
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:50.0) Gecko/20100101 Firefox/50.0
Guest

Re: Clickjacking on Humble (Recaptcha)

Post by Guest »

barbaz wrote:Report ID?
After it had been working a few times, today the warning popped up again with Report ID 67554 and "Potential Clickjacking Attack / Attempted UI-Reconsignment ... partly hidden element ...". This is happening on a DHL website that ought to be trustworthy. I'm sorry, all this is pretty much double Dutch to me, which is why I like to rely on NoScript.

Anke
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:50.0) Gecko/20100101 Firefox/50.0
Guest Ing

Re: Clickjacking on Humble (Recaptcha)

Post by Guest Ing »

I had the same issue on humble bundle: report ID 691805

I also encountered this on a recaptcha on another website (https://ing.dk/scientariet/sporg): Report ID 691807
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:50.0) Gecko/20100101 Firefox/50.0
Post Reply