Noscript.net
Q:
How does NoScript protect me from Clickjacking and other UI-redressing attacks? A:
Default protections provided by NoScript, i.e. JavaScript and plugin blocking can prevent most clickjacking attacks.
To be 100% protected against clickjacking, though, you should enable also Forbid IFRAME; and possibly apply these restrictions to trusted sites as well.
While some users are confortable with these ultra-hardened settings, they can get cumbersome for others.
Fortunately, since version 1.8.2 NoScript provides a new default kind of protection called ClearClick, which defeats clickjacking no matter if you block frames or not.
Tuesday, November 18, 2008
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment