Facebook not serious to fix 'Clickjacking' epidemic

By siliconindia   |   Wednesday, 16 June 2010, 21:31 IST   |    5 Comments
Printer Print Email Email
Facebook not serious to fix 'Clickjacking' epidemic
Bangalore: Nearly 95 percent of the Facebook users believe that the social networking site is not doing enough to prevent the online epidemic clickjacking. IT security and data protection firm, Sophos has polled 600 internet users asking: "Do you think Facebook is doing enough to stop clickjacking worms?" Of those polled, 95 percent voted no, emphasizing the urgent need for Facebook to fix the problem. The clickjacking, exploit the 'Like' button facility by automatically updating a user's Facebook page to say that they 'like' a third-party webpage Once the user clicked, the link takes the user through to a page containing an instruction, such as asking them to click a button to confirm that they are over 18. However, wherever they click on the page it adds a link to their own Facebook profile saying they have also "liked" the site Tuesday, the latest widespread attack struck Facebook users, tricking them into 'liking' a webpage entitled '101 Hottest Women in the World' with a picture of Jessica Alba. 'Clickjacking' for now, is harmless, they demonstrate an exploitable weakness in the way that Facebook works, putting users at potential risk from further malware or phishing attacks. "What's clear is that Facebook needs to set up a proper early warning system to alert users about breaking threats. It seems wrong that the only place where Facebook users can read about the latest attacks is on the pages run by security vendors on Facebook, rather than Facebook's own security pages," said Graham Cluley, Senior Technology Consultant at Sophos.