Page 1 of 1

Potential click-jacking attack at T-Online Musicloade login

Posted: Fri Oct 30, 2009 7:35 pm
by Piano
Hello, I cannot log into Musicload; when I try it I get the message from No Script, that there's a Potential click-jacking attack with trial of UI-address-change. I'm advised to let it blocked. But now I cannot login.

What can I do?

Re: Potential click-jacking attack at T-Online Musicloade login

Posted: Fri Oct 30, 2009 8:19 pm
by Giorgio Maone
Are you using any 3rd party password manager?
Could you use the "Report" button in the ClearClick warning dialog and tell me the assigned ID?

Re: Potential click-jacking attack at T-Online Musicloade login

Posted: Sat Oct 31, 2009 2:54 pm
by Piano
I don't use any password manager. The last report ID is 489442.

Re: Potential click-jacking attack at T-Online Musicloade login

Posted: Sun Nov 01, 2009 11:31 pm
by Giorgio Maone
Unfortunately this is due to many objects from different sites being overlapped on that page.
The easiest workaround is adding "www.musicload.de" to your noscript.clearClick.exceptions about:config preference.

Re: Potential click-jacking attack at T-Online Musicloade login

Posted: Mon Nov 02, 2009 9:07 pm
by Piano
I'm not very skillful concerning "about:config"; can I also unlock the element on the click-cklear -warning-popup and change the click-clear-protection to "trustable site"?

Re: Potential click-jacking attack at T-Online Musicloade login

Posted: Mon Nov 02, 2009 9:25 pm
by Giorgio Maone
Piano wrote:I'm not very skillful concerning "about:config"; can I also unlock the element on the click-cklear -warning-popup and change the click-clear-protection to "trustable site"?
Yes, you can unlock it, but you'll have the same problem next time you start your browser.
Alternatively, you can uncheck the "trusted" box: in this case, ClearClick will protect you only on untrusted sites, which is acceptable but less safe than excepting this site only as suggested above.

Re: Potential click-jacking attack at T-Online Musicloade login

Posted: Tue Nov 03, 2009 7:42 pm
by Piano
Thank you very much for your help!