De-Anonymization via Clickjacking in 2019
m417z.com
m417z.com
I'm not going to spoil anything. If you haven't clicked on the link, you should. It's not malicious, but it does demonstrate the vulnerability.
IP gives you more than just location. If you own a website, and someone from an IP visits your website around the same time as this log, there's probably a good chance they're the same person. So you could then correlate a username on your website with a Facebook profile.
The whole point of potential attack is to correlate a username on the attacker's website with a Facebook profile.
https://m417z.com/De-anonymization-via-Clickjacking-in-2019/...
I tried it in latest Firefox with uBlock & HTTPS Everywhere and it leads me to a 'captcha' page similar to Cloudflare's but there's no actual captcha box. Nothing seems to happen...
Is it uBlock protecting me or is it that I've completely disabled all third party cookies?
Although these days I'm aware that most large tracking companies are probably going beyond just 3rd party cookies and building shadow profiles based on device fingerprinting which as it stands is effectively impossible to avoid without crippling modern browsers.
> Having tried several solutions, I came to the conclusion that blocking third party cookies is the best mitigation for clickjacking.
NoScript maybe?
https://m417z.com/images/De-anonymization-via-Clickjacking-i...
And here's a link that lets you reveal the attack:
https://m417z.com/De-anonymization-via-Clickjacking-in-2019/...
[1] https://www.adobe.com/support/security/advisories/apsa08-08....