Malicious camera spying using ClickJacking

Update: Adobe has fixed this issue by framebusting the Settings Manager pages. Now, 99.9% of the users are protected from this specific exploit. Congrats on the fast response. —-

Turn every browser into a surveillance zombie. The wet dream of every private eye and peeping tom. Imagine this scenario, you play a short game on the web and by doing that you unknowingly grant someone full access to your webcam and microphone.

I’ve made a live demo of it in here, this demo won’t listen or record any of your input.

If you don’t want to try it or don’t have a webcam connected, then check out the video.

[kml_flashembed movie="http://www.youtube.com/v/gxyLbpldmuU" width="450" height="376" /]

When I’ve first heard about ClickJacking and how Adobe is concerned about it, I thought that the Flash Player Security Dialog must have been compromised. But the Security Dialog does a good job disabling itself when you try to mess with it’s visibility through DHTML. Unless there’s some 0-day issue with the Dialog it’s probably relatively safe.

The problem here is the Flash Player Setting Manager, this inheritance from Macromedia might be the Flash Player security Achilles heel.

I’ve written a quick and dirty Javascript game that exploit just that, and demonstrate how an attacker can get a hold of the user’s camera and microphone. This can be used, for example, with platform like ustream, justin and alike or to stream to a private server to create a malicious surveillance platform.

I’ve made it as a JS game to make it easier to understand, but, bear in mind that every Flash, Java, SilverLight, DHTML game or application can be used to achieve the same thing.

Some of the clicks are real game clicks other are jacked clicks. Every time the click is needed to be jacked the content simply move behind the iframe using z-index

I had doubts about publishing this, but, if I could have understand it so are the bad guys, so it’s better to know about it.

In this case Adobe could have just framebust the pages that holds the Settings Manager. There are two issues with frambusting in this case, it won’t solve all cases (legacy browsers for ex) and will force Adobe to rely on javascript.

Play it here, watch it here

101 thoughts on “Malicious camera spying using ClickJacking

  1. Pingback: Zero Day mobile edition

  2. Pingback: Details of Clickjacking Attack Revealed With Online Spying Demo - Desktop Security News Analysis - Dark Reading

  3. Pingback: hackademix.net » Hello ClearClick, Goodbye Clickjacking!

  4. Pingback: Monyer’s Training Notes » Blog Archive » Clickjacking Details

  5. Pingback: Clickjacking Details | ??'s Blog

  6. Pingback: Hello ClearClick, Goodbye Clickjacking! | ??'s Blog

  7. Pingback: Clickjacking here’s how it works | Ugh!!'s Greymatter Honeypot

  8. Pingback: Clickjacking Details | ???

  9. Pingback: Hello ClearClick, Goodbye Clickjacking! | ???

  10. Pingback: Revelan vulnerabilidad clickjacking - Foros de CHW

  11. Pingback: Clickjacking Attack Revealed

  12. Pingback: Hit the button, Jack! « partikelfernsteuerung

  13. Pingback: The WHATWG Blog » Blog Archive » This Week in HTML 5 - Episode 8

  14. Pingback: Midnight Research Labs - Clickjacking details released

  15. Pingback: Clickjacking for spying? | Maestro Security Blogs

  16. Pingback: Clickjacking: One click to cam spy | The Blog Pirate

  17. Pingback: ClickJacking | Aplikacje internetowe

  18. Pingback: Video: l’uso del Clickjacking per spiare gli utenti ignari | Blog.makernet.it

  19. Pingback: Click jacking - Xtreme CPU

  20. Pingback: "Clickjacking" Details Emerge | Student Tech News

  21. This is Dong-bin(Elisabeth) Kim and I’m a reporter of Information Security 21C, mothly magazine, and Boan news, internet daily news site.
    I’m very impressed, so I’d like to introduce your PoC via our magazine.
    So, if you’re O.K, I’d like to capture you PoC and put it into our magazine.
    Please send comment to me.

  22. Pingback: Firefox Extension Blocks Clickjacking! | TekBlog

  23. Pingback: Liquidmatrix Security Digest » Security Briefing: October 8th (Late Edition)

  24. Pingback: Clickjacking peligrosa vulnerabilidad de los navegadores modernos | AtajoTV

  25. Pingback: Clickjacking Attack Lets Web Sites See, Hear You |

  26. Pingback: Clickjacking : une faille de sécurité touchant Adobe Flash Player

  27. Pingback: “Clickjacking” Details Emerge | Syber News

  28. Pingback: ???????????? ??????????? ????? Clickjacking | Raz0r.name - ???? ? web-????????????

  29. Pingback: TechOnlineNews.com » Adobe stopft Flash-Player-Lücke

  30. Pingback: La France d’en bas » Blog Archive » Le ClickJacking utilise flash pour vous filmer à votre insu

  31. Pingback: ClickJacking Exploit : FraudO.com

  32. Pingback: Apukeittiö.fi » Blog Archive » ClickJacking tai UI Redressing

  33. Pingback: ew-bloggt » Forscher enthüllen Details zu Clickjacking-Attacken

  34. Pingback: ????????????????????? - GENMICHA | ????

  35. Pingback: ® NoScript - Addon untuk Mencegah ClickJacking

  36. Pingback: Ajaxian » This Week in HTML 5: Web Forms 2, Search, and more

  37. Pingback: Security Ninja Blog | Clickjacking

  38. Pingback: ???? ????? » ???? » Hello ClearClick, Goodbye Clickjacking! - ???? ?????

  39. Pingback: Adobe’s Workaround for “Clickjacking” Issue, and What You Can Do Now

  40. Pingback: Adobe fixes ‘clickjacking’ flaw | TechHairBall.com

  41. Pingback: Telecom,Security & P2P » [Chinese]clickjacking??

  42. Pingback: Clickjacking: Potentially harmful web browser exploit | Network Administrator | TechRepublic.com

  43. Pingback: El Clickjacking y como afecta a las instituciones « robert dice…

  44. Pingback: Flash Security: Clickjacking the Webcam : TroyWorks

  45. Pingback: Clickjacking Details | Small Business System

  46. Pingback: Application Security Talk » Clickjacking: Do you see what I see?

  47. Click Jacking has long since been called by search engine marketers… u need a new term.

    what click jacking really is is swapping in your own ads into someone elses page often by overlaying or using javascript or filtering their content

  48. Pingback: Preventing Clickjacking with Framebusting - KeepItLocked.net

  49. Pingback: Moja prednáška na WebExpo Praha 2008

  50. Pingback: Packets of Consciousness » Clearjacking: So How Fun is This, Now?

  51. Pingback: Marco’s Webdev Notepad » Blog Archive » Clickjacking

  52. Pingback: Brown Tips » Blog Archive » What IS ClickJacking

  53. Pingback: Prominent Security » Twitter, and the Popularity of Clickjacking.

  54. ction, please visit the blog post of Flash developer Guy Aharonovsky, where he demonstrates in a video how a user unintentionally changes his browser’s security settings while playing a JavaScript

  55. Pingback: Flash + Internet = Big Brother is watching you

  56. Pingback: Dipl.-Inform. Carsten Eilers

  57. Pingback: Dipl.-Inform. Carsten Eilers

  58. Pingback: John Smith’s younger brother, Adam | GUYA.NET

  59. Pingback: Preventing Clickjacking with Framebusting | Keep It Locked

  60. action, please visit the blog post of Flash developer Guy Aharonovsky, where he demonstrates in a video how a user unintentionally changes his browser’s security settings while playing a JavaScript

  61. Clickjacking is a relatively new threat to Web applications for, which in its short history, but damage done several times already. I can only recommend everyone to be vigilant.

  62. Pingback: HOW TO: Spy on the Webcams of Your Website Visitors » Feross.org

  63. Pingback: Adobe to plug Flash-related Webcam spying hole - Gadsit.com

  64. Pingback: Adobe to plug Flash-related Webcam spying hole | samosony

  65. Pingback: Adobe to plug Flash-related Webcam spying hole | Manchester IT Services Blog

  66. Pingback: Adobe to plug Flash-related Webcam spying hole » 99dzh

  67. Pingback: Adobe to plug Flash-related Webcam spying hole - TECHNOLOGY GADGETS – TECHNOLOGY GADGETS

  68. Pingback: Adobe to plug Flash-related Webcam spying hole | News & Current Events

  69. Pingback: Adobe to plug Flash-related Webcam spying hole

  70. Pingback: Adobe to plug Flash-related Webcam spying hole « Internet, Tech & Securities

  71. Pingback: Adobe to Fix Flash Flaw That Allows Webcam Spying | Bytes News

  72. Pingback: Adobe to Fix Flash Flaw That Allows Webcam Spying | Got2.Me

  73. Pingback: Adobe to fix Flash flaw that allows webcam spying - TECHNOLOGY GADGETS – TECHNOLOGY GADGETS

  74. Pingback: Adobe to plug Flash-related Webcam spying hole | Myfriendpal

  75. Pingback: Adobe to Fix Flash Flaw That Allows Webcam Spying | Tech Dott - Daily Technology News Magazine

  76. Pingback: El fallo de Adobe que permitía espiar a los usuarios por sus webcams | SOLO INFORMATICA, POR MANUEL MURILLO GARCIA

  77. Pingback: El fallo de Adobe que permitía espiar a los usuarios por sus webcams « netsolone

  78. Pingback: Eurosas.com - Soporte y mantenimiento de equipos informáticos

  79. Pingback: | Fremont Computer Repair

  80. Pingback: Webcam ClickJacking Revived | GUYA.NET

  81. Pingback: Webcam ClickJacking Revived | Hire Flash Developers

  82. Pingback: El Noguer | Espiar amb la webcam

  83. Pingback: Adobe Flash Bug | Spy On The Webcams of Your Website Visitors

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>