<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Zoiz Blog &#187; click-jacking</title>
	<atom:link href="http://zoiz.web.id/category/click-jacking/feed" rel="self" type="application/rss+xml" />
	<link>http://zoiz.web.id</link>
	<description>Was a Web Application Security Blog</description>
	<lastBuildDate>Tue, 17 Aug 2010 05:57:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>The Net of Worms &#8211; ClickJacking Delivered Worm</title>
		<link>http://zoiz.web.id/logical/the-net-of-worms-clickjacking-delivered-worm.html</link>
		<comments>http://zoiz.web.id/logical/the-net-of-worms-clickjacking-delivered-worm.html#comments</comments>
		<pubDate>Tue, 09 Dec 2008 07:31:38 +0000</pubDate>
		<dc:creator>Zoiz</dc:creator>
				<category><![CDATA[CSRF]]></category>
		<category><![CDATA[Logical]]></category>
		<category><![CDATA[click-jacking]]></category>
		<category><![CDATA[ClickJacking]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=155</guid>
		<description><![CDATA[When talking about ClickJacking, people will first think how to use it to Hijack Web Cam or microphone. Let&#8217;s forget about webcam jacking thingies this time. Been thinking of how to use iFrame redressing (ClickJacking) techniques to exploit web application security. Finally my mind lands to a word, which is known as &#8216;Worm&#8217;. Just like [...]]]></description>
			<content:encoded><![CDATA[<p>When talking about <a href="http://zoiz.web.id/it-news/clickjacking-or-not-proof-of-concept-video-webcam-clickjacking.html" target="_blank">ClickJacking</a>, people will first think how to use it to Hijack Web Cam or microphone. Let&#8217;s forget about webcam jacking thingies this time. Been thinking of how to use iFrame redressing (<a href="http://zoiz.web.id/it-news/clickjacking-or-not-proof-of-concept-video-webcam-clickjacking.html" target="_blank">ClickJacking</a>) techniques to exploit web application security. Finally my mind lands to a word, which is known as &#8216;Worm&#8217;.</p>
<p>Just like the <a href="http://zoiz.web.id/csrf/click-jacking-on-joomla-powered-site-video-poc.html" target="_blank">Click-Jacking style Joomla CMS hijacking</a>. <a href="http://zoiz.web.id/it-news/clickjacking-or-not-proof-of-concept-video-webcam-clickjacking.html" target="_blank"></a><a href="http://zoiz.web.id/category/csrf" target="_blank">CSRF</a> and Automation are needed to infect blogs, CMS, forums, and etc. Possible? Yes indeed!</p>
<p>Scenario :</p>
<ul>
<li>Victim log in to his/her blog, and does not sign out from it.</li>
<li>Victim visits a malicious site with Click-Jacking, any clicks there will trigger a CSRF attack which will attempt to insert a script into victims blog theme. (Just like WordPress Theme Editor)</li>
<li>The script will generate an iFrame containing Click-Jacking</li>
<li>Now the victim&#8217;s blog become a zombie that will attempt to infect all his/her blog&#8217;s visitors blog.</li>
</ul>
<p>Isn&#8217;t it lovely? Just a thought . . .</p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/logical/the-net-of-worms-clickjacking-delivered-worm.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Click-jacking on Joomla Powered Site Video PoC</title>
		<link>http://zoiz.web.id/csrf/click-jacking-on-joomla-powered-site-video-poc.html</link>
		<comments>http://zoiz.web.id/csrf/click-jacking-on-joomla-powered-site-video-poc.html#comments</comments>
		<pubDate>Fri, 28 Nov 2008 06:39:26 +0000</pubDate>
		<dc:creator>Zoiz</dc:creator>
				<category><![CDATA[CSRF]]></category>
		<category><![CDATA[click-jacking]]></category>

		<guid isPermaLink="false">http://zoiz.web.id/?p=121</guid>
		<description><![CDATA[Here is the Click-jacking Proof Of Concept video made by me. On the video, I show you how to pawn or hack a joomla powered site using click-jacking. How it works : - First a victim logged into his Joomla Powered site Administration Control Panel - He didn&#8217;t logged out from the service - He [...]]]></description>
			<content:encoded><![CDATA[<p>Here is the Click-jacking Proof Of Concept video made by me. On the video, I show you how to pawn or hack a joomla powered site using click-jacking.</p>
<p>How it works :</p>
<p>- First a victim logged into his Joomla Powered site Administration Control Panel</p>
<p>- He didn&#8217;t logged out from the service</p>
<p>- He visited a malicious site</p>
<p>- He clicked on something (anything on the page)</p>
<p>- By the time he clicked, his Joomla Powered site password has been changed without his notice</p>
<p><span id="more-121"></span></p>
<p>Combining <a href="http://zoiz.web.id/it-news/clickjacking-or-not-proof-of-concept-video-webcam-clickjacking.html" target="_blank">Click-jacking</a> &amp; <a href="http://zoiz.web.id/category/csrf" target="_blank">CSRF</a>, the clicked trigger a password change request to the Joomla site using the victim privilege. Thus the attack was success, the victim&#8217;s site admin password changed.</p>
<p>Here is the link : <a href="http://www.hackers.web.id/clickjacking-joomla.rar">http://www.hackers.web.id/clickjacking-joomla.rar</a></p>
]]></content:encoded>
			<wfw:commentRss>http://zoiz.web.id/csrf/click-jacking-on-joomla-powered-site-video-poc.html/feed</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
	</channel>
</rss>
