ClearClick Bypass?
Posted: Sun Dec 11, 2011 9:22 am
http://lcamtuf.coredump.cx/clickit/ doesn't seem to trigger ClearClick.
NoScripters and WebSec nerds of all lands, unite!
https://forums.informaction.com/
It took several iterations of "playing the game"therube wrote:I saw neither the warning nor the yellow bar?Tom T. wrote: There is a warning at the top of the browser, "This website has asked to redirect to (the fake bank site)".
> the yellow bar at the top means it isn't a true clickjack attack, but just more NoScript protection against JS redirects.
Perhaps on Fx 8.x or the equivalent SM, But on Fx 3.6.24, default-denying the site's JS means that clicking the POC button produced "no action at all".Not necessarily.
If the attackers site is not allowed, JavaScript is not allowed to run on that site. But JavaScript need not necessarily be required. (You would think in most cases it is, but still.)
Agreed, it was more of a JS redirect. True clickjacking would nvolve layered elements, which I did not see in a brief glance.Not sure if "clickit" falls under the definition of "Clickjacking/ClearClick".
It didn't for me, until the POC site's JS was TA'd. And i got the "warning" after playing the "game" several times.In any case, IMO, the POC is valid, it works.
Not necessarily.
If the attackers site is not allowed, JavaScript is not allowed to run on that site. But JavaScript need not necessarily be required. (You would think in most cases it is, but still.)
In this instance, I was speaking in general, & not specifically about the particular POC.Perhaps on Fx 8.x or the equivalent SM, But on Fx 3.6.24, default-denying the site's JS means that clicking the POC button produced "no action at all".
Perhaps it is another "improvement" in newer Fx and SM.
Could you explain what we're supposed to see, or not, cause I'm not sure I'm seeing any change?v 2.2.4rc2
==========================================================================
+ [ClearClick] Enhanced protection against same-window timing attacks
with moving pointer (thanks Michal Zalewski for PoC)
So I suppose I lost