Clickjacking on Facebook Connect ?

cethir
cethir Posts: 6 Arc User
edited July 2012 in General Discussion
I don't know exactly when this was implemented as I haven't tried to get a blessing in a while, but some time recently a Clickjacking element has been added to the facebook connect page (it activates upon clicking on the fb log in button).
Since I didn't click it (and am no expert with such things anyway), I don't know to what degree it is malicious, but I'd like to warn you all. It might be a good idea not to click this button for now.
Also, if somebody familiar with such things knows a safe way around this or can find out what exactly this one does, that would be nice to know as well. Thanks.
Post edited by cethir on

Comments

  • Cimon - Harshlands
    Cimon - Harshlands Posts: 279 Arc User
    edited July 2012
    this is generally malware on your own pc i had the same issue with this a while back for other sites not games but general stuff like google id click the link in front of me and it would send me somewhere completely different its a pretty standard malware thing just run anti virus or anti whatever and it should fix it pay attention to what site it sends you too as well because it could be a clue as to what your specificly infected with
    [SIGPIC][/SIGPIC]ty mystic man for the sig
  • Decus - Dreamweaver
    Decus - Dreamweaver Posts: 5,033 Arc User
    edited July 2012
    Lol, I read this and thought "clickjacking" was something pseudo-inappropriate. Sorry, couldn't help it.

    To the OP: I suggest Malwarebytes, Spybot, or Hitman Pro.
    Proving that not only archers do math since 2009. b:victory
    Current math challenge: pwi-forum.perfectworld.com/showthread.php?t=1029711&page=45
    [SIGPIC][/SIGPIC]
    "Any skills that can be used to kill you will interrupt BB when successful." -truekossy | "...Sage archers are kind of like Mac owners. They are proud of the weirdest and most unnecessary things." -Aesthor | "We ALL know Jesus doesn't play PWI. He may have suffered a lot for humanity, but he'd NEVER punish himself this way." -Abstractive | "I approve of bananas." -SashaGray
  • cethir
    cethir Posts: 6 Arc User
    edited July 2012
    I appreciate your help -- thank you.

    It seems to me, however, that we're talking about two different things here. To clarify what I mean, Clickjacking is also kown as UI Redressing, further explained here: http://noscript.net/faq#clearclick (see #7).
    I doubt it is malware on my computer since I've only ever noticed this when clicking the 'fb log in' button on PWI's facebook connect page. It wouldn't surprise me if this was implemented by facebook in order to gain more user data, but it might be something entirely different as well.
  • LividLemur - Dreamweaver
    LividLemur - Dreamweaver Posts: 126 Arc User
    edited July 2012
    dunno but if you already have facebook up, you wont need to click anything after logging into pwi (forums, w/e). Just go to the blessing page and it will see that you are already connected to facebook .. and as such u can just grab your blessing
  • Slegtst - Dreamweaver
    Slegtst - Dreamweaver Posts: 595 Arc User
    edited July 2012
    That whole facebook connect thing is bugged as hell.

    Also: /inbe4Sylen
  • cethir
    cethir Posts: 6 Arc User
    edited July 2012
    *bump*

    Is there really nobody who knows something about this ? Maybe even someone from PWI staff (well, was worth a try right ?).
  • cethir
    cethir Posts: 6 Arc User
    edited July 2012
    *bump*