ClickJacking Error on Blogger/Blogspot (Google)
- GµårÐïåñ
- Lieutenant Colonel
- Posts: 3376
- Joined: Fri Mar 20, 2009 5:19 am
- Location: PST - USA
- Contact:
ClickJacking Error on Blogger/Blogspot (Google)
I have never had this issue but suddenly today I am getting this error (Report# 335644) and I was wondering if you can tell me what changed?
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2
Re: ClickJacking Error on Blogger/Blogspot (Google)
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.23) Gecko/20090825 SeaMonkey/1.1.18
- Giorgio Maone
- Site Admin
- Posts: 9539
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: ClickJacking Error on Blogger/Blogspot (Google)
@GµårÐïåñ:
were you logged in or not?
Where did you click exactly?
were you logged in or not?
Where did you click exactly?
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2 (.NET CLR 3.5.30729)
- GµårÐïåñ
- Lieutenant Colonel
- Posts: 3376
- Joined: Fri Mar 20, 2009 5:19 am
- Location: PST - USA
- Contact:
Re: ClickJacking Error on Blogger/Blogspot (Google)
my bad, I reported it and didn't think to mention anything else, since he has access to it. Sorry. It was the blogger site loggin in.
No I was not. I clicked on the "login" on the top bar, it gave me the login page and then when I submit, it gives me the click jack error. When I click the red x on the dialog box, it continues to work fine and the dashboard loads up but I was wondering why the alert? Do you want me to screenshot each step?Giorgio Maone wrote:@GµårÐïåñ:
were you logged in or not?
Where did you click exactly?
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2
- GµårÐïåñ
- Lieutenant Colonel
- Posts: 3376
- Joined: Fri Mar 20, 2009 5:19 am
- Location: PST - USA
- Contact:
Re: ClickJacking Error on Blogger/Blogspot (Google)
Here is the step by step screenshots for the hell of it:
1. Go to the blog:

2. Click on the login on the top brings up this page:

3. Click on login and then it gives the error:

I apologize but there is another report id while I was trying to get these shots for you.
1. Go to the blog:

2. Click on the login on the top brings up this page:

3. Click on login and then it gives the error:

I apologize but there is another report id while I was trying to get these shots for you.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2
Re: ClickJacking Error on Blogger/Blogspot (Google)
OK, I duplicated it.
Not sure how exactly?
All plugins checked except for "No placeholder" & "Collapse blocked".
From the above screenshot, I see that blogger is Allowed.
Wasn't sure what else was, so I Allowed Globally.
There was still a blocked object, & I Allowed *@https://www.google.com.
At that point (I think it was), I got the ClearClick.
Wanted to copy the URL, but instead it opened & the dialog disappeared.
(Guess I can get it from Error Console?) - Yes.
Going through those steps again, I'm not duplicating, so I'm not sure what exactly caused it to transpire.
Not sure how exactly?
All plugins checked except for "No placeholder" & "Collapse blocked".
From the above screenshot, I see that blogger is Allowed.
Wasn't sure what else was, so I Allowed Globally.
There was still a blocked object, & I Allowed *@https://www.google.com.
At that point (I think it was), I got the ClearClick.
Wanted to copy the URL, but instead it opened & the dialog disappeared.
(Guess I can get it from Error Console?) - Yes.
Code: Select all
[NoScript ClearClick] Swallowed event keydown on INPUT/0 at https://www.google.com/accounts/ServiceLoginBox?service=blogger&continue=https%3A%2F%2Fwww.blogger.com%2Floginz%3Fd%3Dhttps%253A%252F%252Fwww.blogger.com%252Fstart%26a%3DALL&passive=true&alinsu=1&aplinsu=1&alwf=true&skipvpage=true&rm=false&showra=1&fpui=2&naui=8
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.1pre) Gecko/20090717 SeaMonkey/2.0b1
- GµårÐïåñ
- Lieutenant Colonel
- Posts: 3376
- Joined: Fri Mar 20, 2009 5:19 am
- Location: PST - USA
- Contact:
Re: ClickJacking Error on Blogger/Blogspot (Google)
Thank you, at least you were able to reproduce once so we know its there and happening, now let's hope Giorgio can figure out what is actually causing it. I can reproduce every time but in your case, at least we have once and hopefully again.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2
- Giorgio Maone
- Site Admin
- Posts: 9539
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: ClickJacking Error on Blogger/Blogspot (Google)
Known issue, very little to do about it.
There's an hidden frame with a Google login box embedded in Blogspot pages, and it happens to automatically get the focus when page loads.
Therefore, as soon as you hit any key, you're typing into the Google login box and, since you can't see where or what you're typing, ClearClick rightly warns you.
Notice that if there was no ClearClick and you had password completion enabled for your Google account, as soon as you hit "Enter" when a BlogSpot page loads, you're automatically logged in your Google account
Maybe a work-around would be a GreaseMonkey script or a Surrogate which restores the focus on the top visible page before you use the keyboard...
There's an hidden frame with a Google login box embedded in Blogspot pages, and it happens to automatically get the focus when page loads.
Therefore, as soon as you hit any key, you're typing into the Google login box and, since you can't see where or what you're typing, ClearClick rightly warns you.
Notice that if there was no ClearClick and you had password completion enabled for your Google account, as soon as you hit "Enter" when a BlogSpot page loads, you're automatically logged in your Google account
Maybe a work-around would be a GreaseMonkey script or a Surrogate which restores the focus on the top visible page before you use the keyboard...
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7 (.NET CLR 3.5.30729)