@flatronL1917 antivirus don't do shit against these types of attacks. Because it's not a virus, it's your browser. An antivirus can't defend you from yourself. And remember you are the one doing the clicks.
Best is: if you don't trust a site, don't use it. And always prefer to type the url of your trusted sites than to click on a link. Even if that link is on google.
i have a new video out requestin for ideas for my next few videos theres alot of takes in there rofl and i try to rap which goes terribly wrong could you please watch it and tell me what u think or maybe an idea, welll thanks byeee :) x
Clickjacking involves getting people to click on things that they don't know they're clicking on. In this case, some of those jumping buttons happened to be in the same place as dialog controls that were on top but invisible -- so the user changed an option and allowed his camera to be used by Flash (a security vulnerability).
How the hell is this not completely illegal? Forget spyware.. it doesn't get ANY more intrusive than this. I've got Adblock and thought that pretty much had me covered. I've toyed with Noscript, but was concerned about it blocking legitimate scripts. It's going on my computers NOW. There is NO justification at all for spying on people in their own homes. Thanks for the video.. very useful in highlighting a completely Orwellian tactic which should be outlawed.
Lol, your over exaderating. This rarley ever happens. And, it is possible to turn your webcam away when not using it, or noticing the light come on. I don't run an AntiVirus of any sort or an script blocker, and I have never been "click Jacked" or even gotten a virus. You just need to be carfull
And then God said... "Let there be NoScript!" And there was NoScript, and God saw it, and it was good. And then God said "Let there be updates!" And there were updates, and God saw it, and it was better!
for the last 6 years i have been unpluggin my webcam cause of this exact reason its so easy to watch people and them not know it i even bought a camera, that turns on two lights very bright and can be seen even if not looking at the webcam just so i know am not being watched
The code he wrote pretends you're playing a game. As a side effect of where you're clicking on the screen (there is an iframe hidden so that you can't see it) he tricks you in to turning your camera on. The game tricks you in to turning your own camera on because you just click wherever it says to.
Goes to show you how terrible HTML is as the backbone of an application framework. I think those insisting building future apps on top of it can keep their mouth shut for a while.
"Goes to show you how terrible HTML is as the backbone of an application framework."
Well, it's true HTML is a Language for Marking up HyperText, and not ideal for serving applications. But the real problem is the trend toward hosting logic on the server and telling the user "run my code".
Even without these major security issues, browsers cede too much control to application developers. Desktop clients have way fewer problems in this regard, but writing them is Hard for neophytes.
The problem has nothing to do with HTML, and everything to do with the security model for trusting JavaScript that originates from a different source than the server hosting the webpage (which is the case for pretty much every advert on the web).
A Same Origin Policy would help here, but it would also cripple a large amount of web functionality (stats tracking tools, adverts, embeddable content etc.).
ClickJacking
hienbeohd251 3 weeks ago
clickjack(dot)net
msncams 5 months ago
genius
Epsilon3G 10 months ago
@flatronL1917 antivirus don't do shit against these types of attacks. Because it's not a virus, it's your browser. An antivirus can't defend you from yourself. And remember you are the one doing the clicks.
Best is: if you don't trust a site, don't use it. And always prefer to type the url of your trusted sites than to click on a link. Even if that link is on google.
kriptonis 1 year ago
This has been flagged as spam show
Windows Live Messenger 2011 Spy Webcam Tool! Download Link On My YouTube Channel! 100% Work!
PornSluts3000 1 year ago
*Sigh* Another malicious programmer who found an awesome "hack" and got his dream of recording people. >.< Good thing it's fixed. :)
roejames12 1 year ago
genius
RandomNinjaOfEvil 1 year ago
@flatronL1917 OR.... you could do the obvious thing and cover the webcam with tape.
Better yet, use an external webcam that you can unplug when you're not using it.
14isacolor 1 year ago
lolol *click* JACKED ... *click* JACKED
So many people musta fallen for this.
AurynThePaladin 1 year ago
This has been flagged as spam show
I jsut saw her totally naked on rudehotgirls . info, and DAMN SHE'S HOT!
mokajen09 2 years ago
Laptops are lame though.
kennyb2142 2 years ago
This has been flagged as spam show
The site below really works.. I got mad prizes from this site and I don't like bullshit and this site is real
try this.. you'll get a extra 1$ for signing up using this link only!
tinyurl,com/la227v
(replace the coma with a dot)
Works for XBOX Cards/Runescape membership/MAPLEStory and any type of game cash you want All free use that link above!
VisitMyLink 2 years ago
This has been flagged as spam show
numeris7 . mybrute . com
BenasCh 2 years ago
This has been flagged as spam show
i have a new video out requestin for ideas for my next few videos theres alot of takes in there rofl and i try to rap which goes terribly wrong could you please watch it and tell me what u think or maybe an idea, welll thanks byeee :) x
iloveacting1995 2 years ago
i dont get this at all
livelaughlovejd 2 years ago
Clickjacking involves getting people to click on things that they don't know they're clicking on. In this case, some of those jumping buttons happened to be in the same place as dialog controls that were on top but invisible -- so the user changed an option and allowed his camera to be used by Flash (a security vulnerability).
fashnek 2 years ago
CRAP
robinho9288 2 years ago
This has been flagged as spam show
when you get time subcribe to my channel & comment your favorite video,I'd appreciate it so much
REVODK 2 years ago
stop spaming
wilsonmitts 2 years ago 2
How the hell is this not completely illegal? Forget spyware.. it doesn't get ANY more intrusive than this. I've got Adblock and thought that pretty much had me covered. I've toyed with Noscript, but was concerned about it blocking legitimate scripts. It's going on my computers NOW. There is NO justification at all for spying on people in their own homes. Thanks for the video.. very useful in highlighting a completely Orwellian tactic which should be outlawed.
ollie501 2 years ago
Lol, your over exaderating. This rarley ever happens. And, it is possible to turn your webcam away when not using it, or noticing the light come on. I don't run an AntiVirus of any sort or an script blocker, and I have never been "click Jacked" or even gotten a virus. You just need to be carfull
kennyb2142 2 years ago
This has been flagged as spam show
h0t chicks love pussy playing - BEST*PORN*CAMS*.*NET
quz4g3 2 years ago
This has been flagged as spam show
ateslixgenc@hotmail com ucmak isteyen bayanlar eklesin =)) webcam sex ( i boy )
AteSzLi 3 years ago
This has been flagged as spam show
SOMEONE TALK TO ME
someone want to chat AQ
13o7 3 years ago
they crippled the real demo for what reason?
shame... it was a news article too.
inachu 3 years ago
And then God said... "Let there be NoScript!" And there was NoScript, and God saw it, and it was good. And then God said "Let there be updates!" And there were updates, and God saw it, and it was better!
moonlitmurloc 3 years ago 30
well spoken
filmmetoo 3 years ago
This comment has received too many negative votes show
Well, actually click jacking is mostly done through CSS. So turning off javascript wont help you now will it?
Zavrion 3 years ago
noscript is not just a "disable javascript" tool. It protects against XSS, ClickJacking, etc.
cristiantm 3 years ago 3
挺好玩的,也挺危险的 - -
limuyuan2008 3 years ago
como ase uno eso
¿?
enceñenme por fabor.
juflomara 3 years ago
Ahh I was wondering how that works, this clears it up a lot.
faenix 3 years ago 3
This has been flagged as spam show
出售 Clickjacking 源码,联系本人。qq373881705
yiyu520413 3 years ago
This has been flagged as spam show
出售 Clickjacking 源码,联系本人。
yiyu520413 3 years ago
。。。。
Baby5683SZS 3 years ago
糟糕
magiemily 3 years ago
hah
axuper 3 years ago
You understand?
magiemily 3 years ago
OH SHI--
youngromh4x0r 3 years ago
for the last 6 years i have been unpluggin my webcam cause of this exact reason its so easy to watch people and them not know it i even bought a camera, that turns on two lights very bright and can be seen even if not looking at the webcam just so i know am not being watched
alexanderstrachan 3 years ago 3
my camera light changes colour when it turns on and so do most others
NicIsNotANinja 3 years ago
but how many people out there would possibly notice the light on or think someone was watching them
mRipX 3 years ago 3
This comment has received too many negative votes show
Sweet you can hijack someones camera by making them click 30 times. Some people have way too much time on their hands.
defyboy 3 years ago
There is one advantage. the 40 year old pervert gets to watch you change.. doesn't that sound fun?
owloncrack 3 years ago
just make sure that whenever your not on webcam with someone, your camera is turned to face the wall or something :)
Quashroom 3 years ago 3
A scary thought to think that it can be done :/
somebodysic 3 years ago
wtf i dont get this
avaxxsamantha 3 years ago
The code he wrote pretends you're playing a game. As a side effect of where you're clicking on the screen (there is an iframe hidden so that you can't see it) he tricks you in to turning your camera on. The game tricks you in to turning your own camera on because you just click wherever it says to.
blank90 3 years ago 4
what is a camera click jack?
shale 3 years ago
sign me up
001196 3 years ago
thanx! this is my last hope to get my webcam started!
pitklong 3 years ago 6
lol
SkaTaku 3 years ago
What'll happen if I click my heels 3 times?
pacattack05 3 years ago
only problem is who would play a pointless gay game like that.. no time limit it doesnt speed up u can clearly tell its a scam.
baalpeteor 3 years ago
But what if it's part of a "calibration" scheme? Don't underestimate people's gullibility; how do you think all of those Kenyans got rich.
bobo304 3 years ago
Bobo304, it's the Nigerians with the scams not the Kenyans.
trojanspirit2 3 years ago
It's just a POC, there are plenty of ways to make this more sneaky.
atatistcheff 3 years ago
or a shitty web game
homergonerson 3 years ago
Obviously, it won't be as simple as this.
heavyccasey 3 years ago
Sadly it is... This problem security problem also exist in various other applications like Jave etc and has not yet been fixed...
Theraxx 3 years ago
Shit will get caught having a wank if im not careful..
zahedieh 3 years ago 5
lmao
vivitar1511 3 years ago
HARHARHARHAR!
I hear that
shockyourmind 3 years ago
Goes to show you how terrible HTML is as the backbone of an application framework. I think those insisting building future apps on top of it can keep their mouth shut for a while.
dlmaniac 3 years ago
"Goes to show you how terrible HTML is as the backbone of an application framework."
Well, it's true HTML is a Language for Marking up HyperText, and not ideal for serving applications. But the real problem is the trend toward hosting logic on the server and telling the user "run my code".
Even without these major security issues, browsers cede too much control to application developers. Desktop clients have way fewer problems in this regard, but writing them is Hard for neophytes.
jjuran 3 years ago
The problem has nothing to do with HTML, and everything to do with the security model for trusting JavaScript that originates from a different source than the server hosting the webpage (which is the case for pretty much every advert on the web).
A Same Origin Policy would help here, but it would also cripple a large amount of web functionality (stats tracking tools, adverts, embeddable content etc.).
kapowaz 3 years ago
Since they're both the same company.
nickmat91 3 years ago
The demo website says: "Update: This demo isn't functional anymore, you can still watch the video [link to this YouTube Page]."
agnostikus 3 years ago
This comment has received too many negative votes show
Macromedia fixed the issue, guys. ;)
Viper007Bond 3 years ago
it doesn't work right on Mac OS X 10.5
I get redirected too, to macromedia's site before I can click
DOSenFreddy 3 years ago
it doesn't work right on suse 11
I get redirected to macromedia's site before I can click
axobeauvi 3 years ago
Saw an article of this over on ZDNET. Genious yet horrifying...the potential...and the threat...
CuracaoChic 3 years ago 2