Welcome | Log In
E-Commerce Times LinuxInsider TechNewsWorld CRM Buyer MacNewsWorld
Exploits & Vulnerabilities

Creepy Clickjacking Bug Lets Hackers Control Webcams

Print Version
E-Mail Article
Reprints

A Flash Player vulnerability could allow attackers to gain control of a user's webcam and microphone, according to a security advisory issued by Adobe. The company has issued a workaround; however a patch won't come until later. As always, Web surfers should be careful where they're clicking.


Think your data is safe? Think again.
Data-stealing malware is on the rise. Trend Micro Enterprise Security, powered by the Trend Micro Smart Protection Network, blocks threats before they reach your network. Learn how. Download our Outthink the Threat eBook or register for a free, on-site assessment.

Software maker Adobe (Nasdaq: ADBE) More about Adobe issued a security advisory Tuesday warning users of its Adobe Flash Player about a vulnerability that could expose them to so-called clickjacking attacks.

Adobe has rated the issue as "critical." The vulnerability is pervasive, affecting all major browsers including Microsoft's (Nasdaq: MSFT) More about Microsoft Internet Explorer, Apple's (Nasdaq: AAPL) Consolidate Mac Servers. Run Windows Server on your Mac. Watch a Demo or Download a Trial. More about Apple Safari and Mozilla's More about Mozilla Foundation Firefox.

While Adobe has not issued a patch for the bug, it has included a workaround in the advisory. The company hopes to address the vulnerability in an upcoming Flash Player update, scheduled for release by the end of October.

Adobe credits security researchers Robert Hansen of SecTheory, Jeremiah Grossman of WhiteHat Security, Eduardo Vela and Matt Mastracci of DotSpots as well as Liu Die Yu for reporting the vulnerability.

Hijacking Clicks

Clickjacking has been around for a while, according to Chris Rodriguez, an analyst at Frost & Sullivan.

"[Clickjacking] comes in many different forms. It has been greatly overlooked by the security community and the criminal community alike. Recently, researchers have demonstrated the dangers of this threat through an Adobe Flash Player vulnerability that would allow an attacker to gain control of a user's microphone and webcam," he told TechNewsWorld.

The exploited vulnerability poses a risk when an attacker is able to trick a user into unwittingly clicking on a link or dialog, according to Adobe.

Clickjacking is usually done by using invisible buttons to get a user to click on something unintentionally, Rodriguez explained.

"However, Adobe's security bulletin is in response to some really nefarious stuff that has been a hot topic lately. Someone has figured out how to use clickjacking to gain access to the user's microphone and webcam. Now that's some scary stuff," he continued.

Celebrity Vulnerabilities

The problem with this and other high-profile security flaws is that they "are quickly weaponized -- in as little as a week, or less," said Rodriguez.

"More importantly, Adobe has only provided a workaround and has not released a patch. Even when a fix is available, Adobe Flash updates are not usually a part of enterprise Linux MPS Pro - Focus on Your Business - Not Your IT Infrastructure. $599.95/month. Click to learn more. patch management cycles. We expect that Adobe is working around the clock to fix this problem and until then, users are at risk unless they research, understand and take the recommended measures against this threat," he added.

As Web browsers become more advanced, these types of threats will continue, according to Phil Hochmuth, a Yankee Group analyst.

"As browsers continue to take on the role of traditional desktop applications, and even desktop operating environments, the increased complexity of plug-ins and browser enhancement tools will no doubt lead to more exploitable flaws and vulnerabilities," he told TechNewsWorld.

Social Networking Toolbox:

Print Version E-Mail Article Reprints More by Walaika Haskins   RSS

Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
ECT News Network Information
Locate Products and Services
Corporate
Reader Services
ECT News Network