Opera users will be protected against Facebook clickjacking operations

Nov 22, 2011 11:56 GMT  ·  By

Zscaler released not long ago a browser plug-in for Chrome, Safari and Firefox that protects users against malicious Facebook elements, and now they made available a version of the tool that works on Opera.

Since clickjacking operations are not that uncommon on Facebook, security solutions providers struggle to make sure their customers are protected against these threats.

Zscaler developed a simple plug-in that alerts users whenever a webpage they visit contains potentially harmful Facebook elements. Just like in the version designed for the other browsers, the Opera plug-in works basically the same way.

When the add-on's icon is green, it means the site is clean, but if it turns red, there is a high possibility that the page contains some malicious codes.

There are two main differences between the Opera variant and the others. The first is that in this case the icon is located in the far right corner of the browser instead of the right part of the address bar and even though it would have been more practical, the way opera is created doesn't allow for such a placement.

The second difference is that the tool cannot detect hidden Facebook widgets in frames or iframes. This limitation occurs because Opera's extension framework doesn't permit frames and iframes to be linked to the top window.

Scripts can be injected in such frames, but since it's hard to determine which tab they belong to, the background page cannot communicate with them inside a tab.

However, this doesn't mean that users will benefit from less protection. In practice, almost none of the hidden Facebook widgets rely on the use of layers of frames or iframes.

The Likejacking tool does a pretty good job, but due to the fact that cybercriminals constantly improve their techniques, this piece of software is also constantly being upgraded to detect even the more hidden threats.

Zscaler Likejacking Prevention 1.0.9 for Opera  is available for download here.