Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: no-s; 1234; 50mm; 6SJ7; Abundy; Action-America; acoulterfan; aristotleman; af_vet_rr; Aggie Mama; ..
Hot-diggity damn.

It's NOT FUD!

The clipboard hijack exploit DOES INDEED work on an OSX Mac with Safari!

Security researcher Aviv Raff has created a proof-of-concept demo to show how easy it is to use Flash with ActionScript code to load (persistently) a malicious URL into a target clipboard. (BEWARE: If you click on the demo link, your clipboard is automatically hijacked and will only be released if the browser window is closed).

For those of you who want to try it, the link to the demo page is below:

WARNING! CLICK AT YOUR OWN RISK!

Demo Link to ClipBoard hijack exploit!

I have found, however, that with a Mac, simply navigating away from the offending hijacking website will end the attack. There is no need to close the browser window.

10 posted on 08/23/2008 8:29:00 PM PDT by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 7 | View Replies ]


To: Swordmaker

Yep, it works, Firefox 3 on Leopard, and it keeps the info in the clipboard.

OTOH, woohoo, it put a text link into my clipboard. I must say I am far less than impressed. Much self-inflicted idiocy must follow for it to be damaging, or much more work to make this effectively malicious.

Still, we’re inching towards that one inevitable day when OS X will finally get an in-the-wild, effective, propagating virus. Until then I’ll keep enjoying not having three protection programs running, sucking up resources.


18 posted on 08/23/2008 9:40:41 PM PDT by antiRepublicrat
[ Post Reply | Private Reply | To 10 | View Replies ]

To: Swordmaker

Oh no! The only answer is to navigate away or close the browser window?!? ;’)


19 posted on 08/23/2008 9:42:14 PM PDT by SunkenCiv (https://secure.freerepublic.com/donate/_______Profile hasn't been updated since Friday, May 30, 2008)
[ Post Reply | Private Reply | To 10 | View Replies ]

To: Swordmaker
I presume this exploit operates by looping the javascript code in the flash to repeatedly copy the bogus URL into the clipboard. That's why the exploit vanishes when you close the browser window.

I really wish there was a way to send a large EMP into the servers owned by these spammers. I'd like to tase the spammers too for good measure!

26 posted on 08/24/2008 4:33:35 AM PDT by 6SJ7
[ Post Reply | Private Reply | To 10 | View Replies ]

To: Swordmaker

Lynx doesn’t seem to suffer from this problem. ;)


32 posted on 08/25/2008 11:20:50 AM PDT by Question_Assumptions
[ Post Reply | Private Reply | To 10 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson