Antwort auf Beitrag Nr.:
39.804.902 von bragg am 11.07.10
19:15:30www.politplatsch
quatsch.com
Wenn Ihr schon keine eigene Meinung habt, lest wenigstens nicht
diesen Quatsch auch noch.
Und Facebook ist auch überall:
Q: What is ClearClick and how does it protect me from
Clickjacking?
A: ClearClick is a NoScript specific anti-Clickjacking protection
module developed during the September 2008 "Clickjacking panic". It
received testing and feedback from many involved security
researches such as RSnake and Jeremiah Grossman (the fathers of the
term "Clickjacking"), Eduardo "Sirdarckcat" Vela and others, and
now it's enabled by default, protecting NoScript users from
Clickjacking everywhere: it even remains active if you switch
NoScript in the less safe Allow scripts globally mode. How does it
work? Clickjacking hides or displaces or partially covers something
you wouldn't want to click, if you could see it in its original
context. ClearClick does the opposite: whenever you click a plugin
object or a framed page, it takes a screenshot of it alone and
opaque (i.e. an image of it with no transparencies and no
overlaying objects), then compares it with a screenshot of the
parent page as you can see it. If the two images differ, a
clickjacking attack is probably happening and NoScript raises a
"ClearClick warning", showing you the contextualized and "clear"
object you were about to click, so you can evaluate by yourself if
that was really something you wanted to do. Of course there are
many subtle technical details involved, but the basic concept is
just simple like that.