<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: All That ClickJazz&#8230;</title>
	<link>http://hackademix.net/2009/01/31/all-that-clickjazz/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Sat, 20 Mar 2010 15:06:45 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: vaibhav</title>
		<link>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10907</link>
		<dc:creator>vaibhav</dc:creator>
		<pubDate>Tue, 10 Feb 2009 18:45:52 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10907</guid>
		<description>Actually this is not the first &#34;cutting edge research&#34; by Aditya K Sood, 
if you have time grab a cup of hot java browse through his numerous
articles (zero code {by 0kn0ck} sadly, which says it all) and you'll be 
half bombed forever.

if you see the logo on his website, it says &#34;Driving Element of Innocuous Minds.&#34; and &#34;Optimized Derivative of Complex Security&#34;. That pretty much
sums everything about him.

Somebody please a leash on this guy.</description>
		<content:encoded><![CDATA[<p>Actually this is not the first &quot;cutting edge research&quot; by Aditya K Sood,<br />
if you have time grab a cup of hot java browse through his numerous<br />
articles (zero code {by 0kn0ck} sadly, which says it all) and you&#8217;ll be<br />
half bombed forever.</p>
<p>if you see the logo on his website, it says &quot;Driving Element of Innocuous Minds.&quot; and &quot;Optimized Derivative of Complex Security&quot;. That pretty much<br />
sums everything about him.</p>
<p>Somebody please a leash on this guy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: justAnotherBob</title>
		<link>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10784</link>
		<dc:creator>justAnotherBob</dc:creator>
		<pubDate>Wed, 04 Feb 2009 22:15:26 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10784</guid>
		<description>argh! my post got scrubbed of JavaScript.</description>
		<content:encoded><![CDATA[<p>argh! my post got scrubbed of JavaScript.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: justAnotherBob</title>
		<link>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10781</link>
		<dc:creator>justAnotherBob</dc:creator>
		<pubDate>Wed, 04 Feb 2009 22:12:51 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10781</guid>
		<description>Beside the point, but... 178 characters!

&lt;a href="http://yahoo.com" rel="nofollow"&gt;Clickjack The Target (http://www.yahoo.com) : (http://evil.hackademix.net)&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Beside the point, but&#8230; 178 characters!</p>
<p><a href="http://yahoo.com" rel="nofollow">Clickjack The Target (http://www.yahoo.com) : (http://evil.hackademix.net)</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Basti</title>
		<link>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10764</link>
		<dc:creator>Basti</dc:creator>
		<pubDate>Tue, 03 Feb 2009 18:24:00 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10764</guid>
		<description>@Amad: This is a easy way to defeat this &#34;attack&#34;.

Would be good if all problems could be solved that easy. :P</description>
		<content:encoded><![CDATA[<p>@Amad: This is a easy way to defeat this &quot;attack&quot;.</p>
<p>Would be good if all problems could be solved that easy. :P</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amad</title>
		<link>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10759</link>
		<dc:creator>Amad</dc:creator>
		<pubDate>Tue, 03 Feb 2009 00:01:31 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10759</guid>
		<description>@Basti: Quick fix for 'lick' jacking (works in firefox):

 Open link in new tab

It doesn't need noscript, works with js enabled! :P

Okay seriously though, surrogate scripts might have some potential in this area</description>
		<content:encoded><![CDATA[<p>@Basti: Quick fix for &#8216;lick&#8217; jacking (works in firefox):</p>
<p> Open link in new tab</p>
<p>It doesn&#8217;t need noscript, works with js enabled! :P</p>
<p>Okay seriously though, surrogate scripts might have some potential in this area</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Basti</title>
		<link>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10755</link>
		<dc:creator>Basti</dc:creator>
		<pubDate>Mon, 02 Feb 2009 19:04:51 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10755</guid>
		<description>@duryodhan: I agree. That is a problem. You can't filter or stop it without having negative impact on other (wanted) things. Would be good if something could warn about it. I guess I should forget about it...

The following is general and not assigned to anyone special: JavaScript isn't per definition bad, but if you take a look at the change-log of Firefox you see that most (theoretical) exploits only work if JavaScript is on.

so thanks for NoScript again. (assigned to Giorgio)</description>
		<content:encoded><![CDATA[<p>@duryodhan: I agree. That is a problem. You can&#8217;t filter or stop it without having negative impact on other (wanted) things. Would be good if something could warn about it. I guess I should forget about it&#8230;</p>
<p>The following is general and not assigned to anyone special: JavaScript isn&#8217;t per definition bad, but if you take a look at the change-log of Firefox you see that most (theoretical) exploits only work if JavaScript is on.</p>
<p>so thanks for NoScript again. (assigned to Giorgio)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ascii</title>
		<link>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10752</link>
		<dc:creator>ascii</dc:creator>
		<pubDate>Mon, 02 Feb 2009 14:53:32 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10752</guid>
		<description>damn Maone, this stuff is terrible, sad for you that have to fight with it. click* attacks </description>
		<content:encoded><![CDATA[<p>damn Maone, this stuff is terrible, sad for you that have to fight with it. click* attacks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: duryodhan</title>
		<link>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10748</link>
		<dc:creator>duryodhan</dc:creator>
		<pubDate>Mon, 02 Feb 2009 07:24:14 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10748</guid>
		<description>basti : because of the way javascript is made and all the evals etc. in it , I think stopping only some type behaviour and not others would be hard to do securely.

But http://research.microsoft.com/en-us/um/people/helenw/papers/bshield-osdi2006.pdf

is something interesting ..</description>
		<content:encoded><![CDATA[<p>basti : because of the way javascript is made and all the evals etc. in it , I think stopping only some type behaviour and not others would be hard to do securely.</p>
<p>But <a href="http://research.microsoft.com/en-us/um/people/helenw/papers/bshield-osdi2006.pdf" rel="nofollow">http://research.microsoft.com/en-us/um/people/helenw/papers/bshield-osdi2006.pdf</a></p>
<p>is something interesting ..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10737</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Sun, 01 Feb 2009 22:19:33 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10737</guid>
		<description>@&lt;b&gt;alexkon&lt;/b&gt;:
Michał (rather than Michal), too :)</description>
		<content:encoded><![CDATA[<p>@<b>alexkon</b>:<br />
Michał (rather than Michal), too :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alexkon</title>
		<link>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10735</link>
		<dc:creator>alexkon</dc:creator>
		<pubDate>Sun, 01 Feb 2009 22:09:00 +0000</pubDate>
		<guid>http://hackademix.net/2009/01/31/all-that-clickjazz/#comment-10735</guid>
		<description>Michal Zalewski, it's w (not v) in his last name.</description>
		<content:encoded><![CDATA[<p>Michal Zalewski, it&#8217;s w (not v) in his last name.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
