SHARE
Facebook X Pinterest WhatsApp

Twitter blocks Clickjacking attack with frame buster

Feb 12, 2009
twitter.jpg

From the

Don

t Click

files:

Over the span of 90 minutes today I got a whole bunch of tweets from people I follow with the message “Don’t Click.” Apparently it was a clickjacking attack. Clickjacking is something that involves getting the user to click on an element that then triggers a second or hidden element or action.  I’ve written on this topic before, which affect sall browsers even though Microsoft has a ‘fix’.

According to a Twitter blog post on the subject “

“..the harm was restricted to constant reposting of the link, but we take
malicious attacks on Twitter users very seriously and this morning we
submitted an update which blocks this clickjacking technique.”

Twitter does not provide details on what the fix is (yet at least), but it’s pretty easy to see what they’ve done. It’s a frame busting script of some sort.

Back on January 30th I wrote about clickjacking twitter and it looks like that particular exploit vector has now been mitigated with the frame buster. With a frame buster the twitter log in element itself cannot be ‘broken out’ of twitter such that it can be hidden on a different site in a hidden frame.

Congrats Twitter on taking action on this – a little later than you could have – but hey it’s the right move.

Recommended for you...

Facebook Becomes Meta, But Did It Move Too Soon?
Rob Enderle
Oct 29, 2021
Microsoft Gets Rid Of Passwords: I Can Almost Hear Angels Singing
Rob Enderle
Sep 17, 2021
Why AMD Has Been So Successful: Mark Papermaster
Rob Enderle
Sep 9, 2021
Another Crazy Week in Cybersecurity
Paul Shread
Jul 2, 2021
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.