你有沒有遇到過這樣的情況?打開一個網頁,出現一個flash廣告框,你點擊“關閉”按鈕,可結果廣告并沒有關閉,卻變成了全屏。知道嗎?這樣的情況在計算機安全領域叫做clickjacking(點擊劫持),也就是說你點擊鼠標的行為被人給控制了。
Clickjacking is a malicious technique of tricking Web users into revealing confidential information or taking control of their computer while clicking on seemingly innocuous Web pages. A vulnerability across a variety of browsers and platforms, a clickjacking takes the form of embedded code or script that can execute without the user's knowledge, such as clicking on a button that appears to “play” a video but actually is tricking users to make their social networking profile information public.
“點擊劫持”是一種惡意攻擊技術,用于跟蹤網絡用戶,獲取其私密信息或者通過讓用戶點擊看似正常的網頁來遠程控制其電腦。很多瀏覽器和操作平臺都有這樣的漏洞?!包c擊劫持”技術可以用嵌入代碼或者文本的形式出現,在用戶毫不知情的情況下完成攻擊,比如:點擊一個表面顯示是“播放”某個視頻的按鈕,而實際上完成的操作卻是將用戶的社交網站個人信息改為“公開”狀態(tài)。
The word clickjacking first appeared in 2008, coined by Internet security experts Robert Hansen and Jeremiah Grossman. The term is, of course, a blend of the words click and hijacking (=illegally taking control of something).
“點擊劫持”(clickjacking)這個詞首次出現在2008年,是由互聯網安全專家羅伯特?漢森和耶利米?格勞斯曼首創(chuàng)的。這個詞其實是“點擊”(click)和“劫持”(hijacking)兩個詞組合而成的。
相關閱讀
(中國日報網英語點津 Helen 編輯)