This one sounds pretty bad:
In a nutshell, it’s when you visit a malicious website and the attacker
is able to take control of the links that your browser visits. The problem
affects all of the different browsers except something like lynx. The issue has
nothing to do with JavaScript so turning JavaScript off in your browser will not
help you. It’s a fundamental flaw with the way your browser works and cannot be
fixed with a simple patch. With this exploit, once you’re on the malicious web
page, the bad guy can make you click on any link, any button, or anything on the
page without you even seeing it happening.
The only defense might be Firefox + NoScript according to the guy who developed NoScript.
Here's more info on it from one of the two guys who were going to present it.
Comments