NoScript ClearClick Warning For Wordpress.com Stats
For those unaware, NoScript is a wonderful Firefox addon that keeps your browser secure. In the words of the development team,
The NoScript Firefox extension provides extra protection for Firefox, Flock, Seamonkey and other mozilla-based browsers: this free, open source add-on allows JavaScript, Java, Flash and other plugins to be executed only by trusted web sites of your choice (e.g. your online bank), and provides the most powerful Anti-XSS protection available in a browser.
I have recently run into a problem which relates to a ClearClick Clickjack attempt warning when using Wordpress.com Stats with Wordpress 2.6.5 and I’ve been unable to find a solution. I have upgraded to the latest version of both the Wordpress.com Stats plugin and Wordpress itself. Wordpress.com Stats is a flash based plugin. When signing in to my dashboard I am presented with a login box for my stats which looks like this:
When I click on the textbox for username and press my first key I receive a NoScript Potential Clickjacking / UI Redressing Attempt pop-up warning. The link that it claims is being clickjacked is http://dashboard.wordpress.com/wp-login.php?action=auth&redirect_to=http%3A%2F%2Fdashboard.wordpress.com%2Fwp-admin%2Findex.php%3Fpage%3Destats%26blog%3D3985288%26noheader%3Dtrue%26chart%26unit%3D1%26width%3D463%26height%3D228 which is just a link to the embedded Wordpress.com statistics.
My questions are these: Should I be worried? Has my Wordpress Admin section been compromised? Does Wordpress have an exploit allowing someone to embed clickjack attempts within my site? Or is this a false positive and nothing to worry about? I’ve been unable to find any other reports of this issue so I’m posting it here and and hope to get to the bottom of this.



A quick and easy way to decide if a ClearClick warning is a false positive or not, is comparing the green-bordered image with the red-bordered you get by clicking on it. The former depicts the “clear” object you’re clicking (i.e. with no transparencies and no objects overlaying it), the latter the way it appears on the page as it is intended by its (possibly malicious) designer.
If the two clearly represent the same thing and it’s what you intended to interact with (like in this case), it’s probably a false positive and I’d appreciate a report on http://noscript.net/forum possibly with both the screenshots.
BTW, are you using latest NoScript version?
Giorgio Maones last blog post..Go Green with NoScript!
[Reply]
@Gorgio
Thanks for the quick reply. Ive posted the information on the forum at http://forums.mozillazine.org/viewtopic.php?f=48&t=826005&p=5142095#p5142095 along with the screenshots.
The difference btween the green and red bordered image when I click is that the image shifts down by half an inch but I am unable to see anything suspicious.
Im using the latest version of NoScript .. just updated it today to be sure.
[Reply]
Leave your response!
Schapelle Corby »
The Next Generation in International Debate
Justtellmewhy.com isn’t just another social networking website. In many ways, it’s the next big step in online communication and learning. It essentially has taken elements from concepts like Wikipedia, Yahoo! Answers and Digg and brought …
True Crime »
On Xena and Murderabilia
There is a stigma that is eternally attached to anyone who collects true crime artifacts. Sure, I have a hard time understanding why someone would pay money for the used socks of a serial killer, but I also have a hard time understanding why someone kills and animal, guts it, mounts it to their wall and calls it “art”. Same goes for people who would pay millions for a dress some starlet wore to the Oscars, a baseball signed by a major leaguer,
web 2.0 »
What is a Tweet and How to Do It? Back To The Basics
At work we are just starting to realize the importance of social networking from a business standpoint and the potential for wild growth and viral advertising. We have a twitter account at work that has …
West Memphis Three »
Victim’s mother believes defendants innocent.
In a telephone interview on Monday, Stevie’s stepfather, Terry Hobbs, confirmed that West Memphis police had videotaped an interview with him within the last three weeks.
Well well well…. After all these years its finally coming …
feed me
Recent Comments
Archives
Archive
Blogroll
Mobile Barcode
This is a 2D-barcode containing the address of ourmobile site.If your mobile has a barcode reader, simply snap this bar code with the camera and launch the site.
Many companies provide barcode readers that you can install on your mobile, and all of the following are compatible with this format: