r/hacking • u/CyberMasterV • 3d ago
DOM-based Extension Clickjacking: Your Password Manager Data at Risk
https://marektoth.com/blog/dom-based-extension-clickjacking/4
2
u/Heclalava 1d ago edited 1d ago
Seems attacks rely on javascript, so blocking scripts with NoScript or similar is good as a primary defense.
I also disabled manual autofill - and switched to copy/paste only.
Plus as per the article I did the following:
Extension settings → site access → "on click"
With this setting, the browser extension will not access the site. The user can temporarily grant access by clicking on the extension icon in the upper right corner.
Edit: moved to the desktop client instead of the browser extension. Seemed the safest move.
-12
u/Novel_Standard_2275 2d ago
Hello reddit I request this Instagram account ben (name of =@tet.eranglong
8
15
u/Imaginary_Page_2127 2d ago
Summary of the attack :)