Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Kaminsky Creates Clickjacking-Killer
Newest First  |  Oldest First  |  Threaded View
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
8/11/2015 | 12:57:35 PM
Re: Clickjacking Killer
Thank you for sharing that insight and perspective, @carofer. It's great to hear from the dev side on this!
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
8/11/2015 | 12:51:53 PM
Clickjacking
Clickjacking is all too prevalent. It's good to see that we are analyzing methods of negating its detrimental effects. Most often this catches non-tech individuals off guard and sometimes even the occassional techie.
carofer
50%
50%
carofer,
User Rank: Apprentice
8/11/2015 | 12:46:15 PM
Clickjacking Killer
It has disturbed me, as a manager of developers, that heavy-handed security restrictions like CORS are invented to thwart exploits like clickjackings. The honest developer is left with the task of working around the restrictions in order to provide mash-ups or other multi-domain user experiences.  It has a very high cost for developers, and, when workarounds such as JSONP are used, the original goals of the restriction are completely defeated, making it all a huge exercise in futility.

The development of the Kaminsky solution is therefore of HUGE significance, and we practitioners welcome it.

Bring it on and maybe we can be done with the kabuki dance of (some) porous security standards!!!

Allan Rofer


Manchester United Suffers Cyberattack
Dark Reading Staff 11/23/2020
As 'Anywhere Work' Evolves, Security Will Be Key Challenge
Robert Lemos, Contributing Writer,  11/23/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25738
PUBLISHED: 2020-11-27
CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credential access, such as a Chrome process that reads credentials from a SQLite database.
CVE-2020-29144
PUBLISHED: 2020-11-27
In Ericsson BSCS iX R18 Billing & Rating iX R18, MX is a web base module in BSCS iX that is vulnerable to stored XSS via an Alert Dashboard comment. In most test cases, session hijacking was also possible by utilizing the XSS vulnerability. This potentially allows for full account takeover, or e...
CVE-2020-29145
PUBLISHED: 2020-11-27
In Ericsson BSCS iX R18 Billing & Rating iX R18, ADMX is a web base module in BSCS iX that is vulnerable to stored XSS via the name or description field to a solutionUnitServlet?SuName=UserReferenceDataSU Access Rights Group. In most test cases, session hijacking was also possible by utilizing t...
CVE-2020-29136
PUBLISHED: 2020-11-27
In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).
CVE-2020-29137
PUBLISHED: 2020-11-27
cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).