The Clipboard hijacks continue....

I see that The Register has picked up on the story: Mystery web attack hijacks your clipoard.  Reading through the comments is illuminating, as always.

Oh, and by the way, if you hear of anybody touting Linux as a panacea, in addition to the few comments from those using Firefox on Linux that were hit, you may want to refer them to this:
Ubuntu user affected - http://ubuntu-virginia.ubuntuforums.org/showthread.php?t=886905

I am well aware that the current crop of fraudware software making the rounds targets Windows, but reality is that there is also fraudware in circulation that targets the MAC and it is only a matter of time before there is an offering for Linux - after all, Linux users are just as at risk from social engineering as anybody else.

While we're on the topic of social engineering, check out the following article - it makes a chill go down the spine, doesn't it? 

Even computer security pros vulnerable to scams

"The ruse concocted by Shawn Moyer, chief information security officer for Agura Digital Security, and Nathan Hamiel, senior consultant for Idea Information Security, worked like this:

They found prominent security figures who didn't have profiles on particular social networking Web sites.

They built up fake profiles by using information from press releases and news articles. Then they built up the profiles' authenticity by sending them around to people who indiscriminately add friends on those sites.

Finally, once the profiles looked legitimate, they identified groups of security professionals on those sites and sent their friend requests to them.

Moyer and Hamiel said they did it three times, each time impersonating a different person. Each time they lured in more than 50 new friends within 24 hours. Some of those people were chief security officers for major corporations and defense industry workers, they said. They declined to identify any of those people."

Comments

# re: The Clipboard hijacks continue....

Tuesday, August 26, 2008 5:52 PM by Mark Odell

> Oh, and by the way, if you hear of anybody touting Linux as a panacea

....then you may want to get that person's name and make sure it's not <A HREF="www.crazyapplerumors.com MacStrawman</A>.

> I am well aware that the current crop of fraudware software making the rounds targets Windows, but reality is that there is also fraudware in circulation that targets the MAC

Reality is also that "targets" is not the same thing as "engages" is not the same thing as "defeats".

(BTW, is there any particular reason you write "MAC" -- referring to the Macintosh, not the Media Access Control address of Ethernet hardware adapters -- in all-caps?)

> and it is only a matter of time before there is an offering for Linux

If so, then until that happens, why not use time to your advantage?

> - after all, Linux users are just as at risk from social engineering as anybody else.

Are they, now?

If Flash Player ran in a <A HREF="sandboxie.com/.../A>, then would it write to the sandbox's pseudo-clipboard, instead of the actual clipboard in memory?