Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

January 17th, 2013, 23:01 GMT · By

BLOG

LinkedIn Fixes Clickjacking Vulnerability in “Remove Connections” Section – Video

SHARE:

Adjust text size:


LinkedIn has addressed a clickjacking vulnerability in the “remove connections” section of the website. The security hole was discovered by Jovyn Lobo (7h3_j0k3r), a security consultant at Payatu Technologies and the author of the “game | over” web app penetration testing platform.

According to the expert, an attacker could have leveraged the flaw to trick LinkedIn customers into removing some of their existing connections without realizing.

Victims of such an attack would be tricked into thinking that they were clicking on innocent links or buttons, when in reality they would be unwittingly deleting their connections.

The vulnerability was reported to LinkedIn in September 2012, but the company only addressed the issue on January 11, 2013.

The expert says the social media site implemented the X-Frame-Options header to fix the security hole. For more details, check out the POC video published by Lobo.

TELL US WHAT YOU THINK:

1,660 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Foxit Reader 5.4.5 Released to Address Arbitrary Code Execution Vulnerability

Website of Harvard’s School of Engineering and Applied Sciences Hacked

Drupal 7.19 and 6.28 Released to Address XSS, Access Bypass Flaws

Expert Finds Security Holes in Sites of Microsoft, Twilio and ProActive CMS

Experts Identify Zero-Day Vulnerability in Cisco’s Linksys Routers – Video

READER COMMENTS:


Comment #1 by: yoda on 23 Jan 2013, 10:03 UTC reply to this comment

Great Work

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM