OWASP NZ SEP 2011 - Clickjacking for Shells.pdf

(2777 KB) Pobierz
Clickjacking For Shells
OWASP Wellington, New Zealand Chapter Meeting
September 2011
PDF Version
Introductions
Hello Everybody
My name is Andrew Horton aka urbanadventurer
Security Consultant for Security-Assessment.com
Develop security tools
WhatWeb – Web scanner included in BackTrack
URLCrazy – Domain name typo squatting research
and more
Operate MorningStar Security News
You may have seen me giving presentations at Kiwicon
Videos Not Available
This PDF version of the Clickjacking For Shells
presentation does not include videos.
See the video version for demos
Agenda
What is clickjacking?
Clickjacking in the wild
Are web apps vulnerable to clickjacking?
WordPress clickjacking 0day
How to protect your webapp from clickjacking
What is Clickjacking?
You think you’re clicking on the
website you see but no… you’re really
clicking on an
invisible website
you
cannot see that’s right under your
mouse.
Clickjacking affects many browsers
and platforms
First published in 2008 by Jeremiah
Grossman and Robert ―Rsnake‖
Hansen
Zgłoś jeśli naruszono regulamin