<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: IE8&#8217;s &#8220;Clickjacking Protection&#8221; Exposed</title>
	<link>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Wed, 08 Feb 2012 12:13:48 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Konnie30</title>
		<link>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-16318</link>
		<dc:creator>Konnie30</dc:creator>
		<pubDate>Fri, 27 Nov 2009 00:28:11 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-16318</guid>
		<description>It's not so easy to make a nice essays written, preferably if you are concerned. I recommend you to define &lt;a href="http://www.qualityessay.com" rel="nofollow"&gt;buy essay&lt;/a&gt; and to be void from disbelief that your work will be done by paper writing service</description>
		<content:encoded><![CDATA[<p>It&#8217;s not so easy to make a nice essays written, preferably if you are concerned. I recommend you to define <a href="http://www.qualityessay.com" rel="nofollow">buy essay</a> and to be void from disbelief that your work will be done by paper writing service</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Terrel Shumway</title>
		<link>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-11206</link>
		<dc:creator>Terrel Shumway</dc:creator>
		<pubDate>Thu, 26 Feb 2009 22:45:37 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-11206</guid>
		<description>If NoScript, or its functionality is included in mainline Firefox, is that going to interfere with new development? NoScript has a pretty quick release cycle compared with the main browser. I'd hate to see that go away.</description>
		<content:encoded><![CDATA[<p>If NoScript, or its functionality is included in mainline Firefox, is that going to interfere with new development? NoScript has a pretty quick release cycle compared with the main browser. I&#8217;d hate to see that go away.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The WHATWG Blog » Blog Archive » This Week in HTML 5 - Episode 21</title>
		<link>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-10909</link>
		<dc:creator>The WHATWG Blog » Blog Archive » This Week in HTML 5 - Episode 21</dc:creator>
		<pubDate>Tue, 10 Feb 2009 23:02:30 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-10909</guid>
		<description>[...] which relies on web authors to include a Microsoft-proprietary HTTP header. RSnake responds, as does Giorgio Maone (who, by the way, has already integrated Microsoft's proprietary header into his NoScript extension [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] which relies on web authors to include a Microsoft-proprietary HTTP header. RSnake responds, as does Giorgio Maone (who, by the way, has already integrated Microsoft&#8217;s proprietary header into his NoScript extension [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: IE8 clickjacking / ui redressing prevention via X-FRAME-OPTIONSIts &#124; Security and the Net</title>
		<link>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-10719</link>
		<dc:creator>IE8 clickjacking / ui redressing prevention via X-FRAME-OPTIONSIts &#124; Security and the Net</dc:creator>
		<pubDate>Sun, 01 Feb 2009 10:41:58 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-10719</guid>
		<description>[...] that tells Internet Explorer the page is not supposed to be included in a frame. It’s called X-FRAME-OPTIONS; a value of DENY means the page should never be opened in a frame, and SAMEORIGIN only allows it to [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] that tells Internet Explorer the page is not supposed to be included in a frame. It’s called X-FRAME-OPTIONS; a value of DENY means the page should never be opened in a frame, and SAMEORIGIN only allows it to [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackademix.net » All That ClickJazz...</title>
		<link>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-10707</link>
		<dc:creator>hackademix.net » All That ClickJazz...</dc:creator>
		<pubDate>Sat, 31 Jan 2009 21:06:43 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-10707</guid>
		<description>[...] to IE8’s touted Clickjacking protection which will work on pages whose authors adopt the new proprietary X-FRAME-OPTIONS header (now [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] to IE8’s touted Clickjacking protection which will work on pages whose authors adopt the new proprietary X-FRAME-OPTIONS header (now [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackademix.net »</title>
		<link>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-10674</link>
		<dc:creator>hackademix.net »</dc:creator>
		<pubDate>Fri, 30 Jan 2009 00:12:31 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-10674</guid>
		<description>[...] IE8’s “Clickjacking Protection” Exposed  [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] IE8’s “Clickjacking Protection” Exposed  [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-10667</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Thu, 29 Jan 2009 15:25:50 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-10667</guid>
		<description>@&lt;b&gt;Hans Nordhaugh&lt;/b&gt;:
Thanks, I already commented on the &lt;a href="http://www.heise-online.co.uk/security/Popular-browsers-continue-to-be-vulnerable-to-clickjacking-attacks--/news/112518" rel="nofollow"&gt;UK edition of that article&lt;/a&gt;.

Precisely at this moment I was "laughing" with OWASP's Arshan Dabirsiaghi of how many clowns talking "Clickjacking" and nobody (including Heise) grasping even the basic concept...</description>
		<content:encoded><![CDATA[<p>@<b>Hans Nordhaugh</b>:<br />
Thanks, I already commented on the <a href="http://www.heise-online.co.uk/security/Popular-browsers-continue-to-be-vulnerable-to-clickjacking-attacks--/news/112518" rel="nofollow">UK edition of that article</a>.</p>
<p>Precisely at this moment I was &#8220;laughing&#8221; with OWASP&#8217;s Arshan Dabirsiaghi of how many clowns talking &#8220;Clickjacking&#8221; and nobody (including Heise) grasping even the basic concept&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hans Nordhaug</title>
		<link>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-10666</link>
		<dc:creator>Hans Nordhaug</dc:creator>
		<pubDate>Thu, 29 Jan 2009 15:16:18 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-10666</guid>
		<description>@Giorgio

Heise Security bought the secniche.org story and claims that &#34;NoScript obviously does not appear to recognize all variants of Clickjacking.&#34; Just FYI.</description>
		<content:encoded><![CDATA[<p>@Giorgio</p>
<p>Heise Security bought the secniche.org story and claims that &quot;NoScript obviously does not appear to recognize all variants of Clickjacking.&quot; Just FYI.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: decent user</title>
		<link>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-10665</link>
		<dc:creator>decent user</dc:creator>
		<pubDate>Thu, 29 Jan 2009 11:01:26 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-10665</guid>
		<description>Thanks for the ultra fast clarification!

&#62; either he cannot understand Clickjacking, or he’s purposely using the buzzword to get some cheap publicity.

Both I think, referring to your explanation.

Best wishes! And thanks for the great work with NoScript!</description>
		<content:encoded><![CDATA[<p>Thanks for the ultra fast clarification!</p>
<p>&gt; either he cannot understand Clickjacking, or he’s purposely using the buzzword to get some cheap publicity.</p>
<p>Both I think, referring to your explanation.</p>
<p>Best wishes! And thanks for the great work with NoScript!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-10664</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Thu, 29 Jan 2009 10:34:57 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/28/ie8s-clickjacking-protection-exposed/#comment-10664</guid>
		<description>@&lt;b&gt;decent user&lt;/b&gt;:

That guy is an idiot: either he cannot understand Clickjacking, or he's purposely using the buzzword to get some cheap publicity.
His "PoC" is just an laughably over-elaborated version of a simple:
&lt;code&gt;
&#60;a href="http://yahoo.com" onclick=&#34;location='http://xssed.com';return false&#34;&#62;Yahoo&#60;/a&#62;
&lt;/code&gt;
Try it: &lt;a href="http://yahoo.com" onclick="location='http://xssed.com';return false" rel="nofollow"&gt;Yahoo&lt;/a&gt;

That's not Clickjacking by any stretch of imagination, and hardly malicious: you just get on a "surprise" destination, but nothing more since it can't do any of the cross-site evils (e.g. bypassing CSRF protection) of the real thing.</description>
		<content:encoded><![CDATA[<p>@<b>decent user</b>:</p>
<p>That guy is an idiot: either he cannot understand Clickjacking, or he&#8217;s purposely using the buzzword to get some cheap publicity.<br />
His &#8220;PoC&#8221; is just an laughably over-elaborated version of a simple:</p>
<div class="codesnip-container" >&lt;a href=&#8221;http://yahoo.com&#8221; onclick=&quot;location=&#8217;http://xssed.com&#8217;;return false&quot;&gt;Yahoo&lt;/a&gt;</div>
<p>Try it: <a href="http://yahoo.com" onclick="location='http://xssed.com';return false" rel="nofollow">Yahoo</a></p>
<p>That&#8217;s not Clickjacking by any stretch of imagination, and hardly malicious: you just get on a &#8220;surprise&#8221; destination, but nothing more since it can&#8217;t do any of the cross-site evils (e.g. bypassing CSRF protection) of the real thing.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

