<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-3650259870998252242.post1372210369473171347..comments</id><updated>2011-12-17T12:53:11.122+01:00</updated><category term='dialog'/><category term='parity'/><category term='html5'/><category term='bbcode'/><category term='firebug'/><category term='malware'/><category term='false'/><category term='doctrine'/><category term='events'/><category term='include'/><category term='chrome'/><category term='firefox'/><category term='encryption'/><category term='window'/><category term='e4x'/><category term='grep'/><category term='ede'/><category term='video'/><category term='email'/><category term='xss'/><category term='closures'/><category term='wget'/><category term='training'/><category term='niebezpiecznik'/><category term='tab'/><category term='facebook'/><category term='xml'/><category term='pki'/><category term='propel'/><category term='denied'/><category term='select'/><category term='mysql'/><category term='java'/><category term='multiuser'/><category term='talk'/><category term='webdav'/><category term='security'/><category term='openssl'/><category term='padding'/><category term='diff'/><category term='game'/><category term='oracle'/><category term='rest'/><category term='ui'/><category term='android'/><category term='tripledes'/><category term='escape'/><category term='zend framework'/><category term='flickr'/><category term='html'/><category term='signing'/><category term='tostring'/><category term='datetimeconvert'/><category term='pear'/><category term='hijack'/><category term='tree'/><category term='widget'/><category term='magic quotes'/><category term='cracow'/><category term='json'/><category term='svn'/><category term='google'/><category term='modal'/><category term='php5'/><category term='lint'/><category term='csrf'/><category term='3des'/><category term='obfuscation'/><category term='cryptography'/><category term='javascript'/><category term='cache'/><category term='iframe'/><category term='des'/><category term='eval'/><category term='option'/><category term='load'/><category term='websockets'/><category term='youtube'/><category term='sidejacking'/><category term='tumblr'/><category term='http'/><category term='demo'/><category term='sql injection'/><category term='mssql'/><category term='desede'/><category term='track'/><category term='python'/><category term='plugin'/><category term='analysis'/><category term='overloading'/><category term='owasp'/><category term='new pix'/><category term='clickjacking'/><category term='access'/><category term='everonia'/><category term='jsunpack'/><category term='readonly'/><category term='update'/><category term='share'/><category term='hack'/><category term='key'/><category term='tabs'/><category term='php'/><category term='crockford'/><category term='ajax'/><category term='deployment'/><category term='remote'/><category term='sqli'/><category term='freetds'/><category term='refresh'/><category term='ie'/><category term='clickjack'/><category term='regex'/><category term='jquery'/><category term='turing'/><category term='mdb2'/><category term='clone'/><category term='captcha'/><category term='datepicker'/><category term='hardening'/><category term='utf7'/><category term='upload'/><category term='history'/><category term='log'/><category term='search'/><category term='referrer'/><category term='server'/><category term='phar'/><category term='symfony'/><category term='ftp'/><title type='text'>Comments on the world. according to koto: New Facebook clickjacking attack in the wild - fb....</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.kotowicz.net/feeds/1372210369473171347/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3650259870998252242/1372210369473171347/comments/default'/><link rel='alternate' type='text/html' href='http://blog.kotowicz.net/2009/12/new-facebook-clickjagging-attack-in.html'/><author><name>Krzysztof Kotowicz</name><uri>https://profiles.google.com/111743409761183951147</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-ADnDC5o75NA/AAAAAAAAAAI/AAAAAAAAE1w/rnOv95ckHn4/s512-c/photo.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>7</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3650259870998252242.post-2767230086159348322</id><published>2011-12-17T12:53:11.123+01:00</published><updated>2011-12-17T12:53:11.123+01:00</updated><title type='text'>I like the script, thank you for sharing</title><content type='html'>I like the script, thank you for sharing</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3650259870998252242/1372210369473171347/comments/default/2767230086159348322'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3650259870998252242/1372210369473171347/comments/default/2767230086159348322'/><link rel='alternate' type='text/html' href='http://blog.kotowicz.net/2009/12/new-facebook-clickjagging-attack-in.html?showComment=1324122791123#c2767230086159348322' title=''/><author><name>Regex84</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.kotowicz.net/2009/12/new-facebook-clickjagging-attack-in.html' ref='tag:blogger.com,1999:blog-3650259870998252242.post-1372210369473171347' source='http://www.blogger.com/feeds/3650259870998252242/posts/default/1372210369473171347' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1348608934'/></entry><entry><id>tag:blogger.com,1999:blog-3650259870998252242.post-2147753589657290016</id><published>2010-06-05T12:37:30.615+02:00</published><updated>2010-06-05T12:37:30.615+02:00</updated><title type='text'>@nineza

Yeah, it looks silly but nevertheless thi...</title><content type='html'>@nineza&lt;br /&gt;&lt;br /&gt;Yeah, it looks silly but nevertheless this particular naive clickjacking attack succeeded back then. Many people clicked the button - of course FB did not publish any statistics, butit was popular among my friends and it was big enough to trigger blogosphere attention. &lt;br /&gt;&lt;br /&gt;Just try to imagine  what would happen if this was more elaborate.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3650259870998252242/1372210369473171347/comments/default/2147753589657290016'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3650259870998252242/1372210369473171347/comments/default/2147753589657290016'/><link rel='alternate' type='text/html' href='http://blog.kotowicz.net/2009/12/new-facebook-clickjagging-attack-in.html?showComment=1275734250615#c2147753589657290016' title=''/><author><name>Krzysztof Kotowicz</name><uri>http://www.blogger.com/profile/11516786094492717236</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.kotowicz.net/2009/12/new-facebook-clickjagging-attack-in.html' ref='tag:blogger.com,1999:blog-3650259870998252242.post-1372210369473171347' source='http://www.blogger.com/feeds/3650259870998252242/posts/default/1372210369473171347' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1270688555'/></entry><entry><id>tag:blogger.com,1999:blog-3650259870998252242.post-3414961745568985396</id><published>2010-06-05T06:58:24.495+02:00</published><updated>2010-06-05T06:58:24.495+02:00</updated><title type='text'>Well, that&amp;#39;s nice of us being able to be hacke...</title><content type='html'>Well, that&amp;#39;s nice of us being able to be hacked.&lt;br /&gt;&lt;br /&gt;But seriously, that is a POOR attempt at confusing people. That would hardly confuse anyone, you can see the other boxes have random letters, and that just HAPPENS to have a proper 5 letter word called &amp;quot;Share&amp;quot;, with the exact same background colour as the Facebook share button...&lt;br /&gt;&lt;br /&gt;Meh, oh well. But they could&amp;#39;ve atleast BOTHERED to do SOMETHING to make it look better.&lt;br /&gt;Not saying they should&amp;#39;ve though, otherwise facebook would be even more spread with this. xD&lt;br /&gt;&lt;br /&gt;But that IS a poor attempt to be honest...</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3650259870998252242/1372210369473171347/comments/default/3414961745568985396'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3650259870998252242/1372210369473171347/comments/default/3414961745568985396'/><link rel='alternate' type='text/html' href='http://blog.kotowicz.net/2009/12/new-facebook-clickjagging-attack-in.html?showComment=1275713904495#c3414961745568985396' title=''/><author><name>Nineza</name><uri>http://www.blogger.com/profile/15052035932229031097</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.kotowicz.net/2009/12/new-facebook-clickjagging-attack-in.html' ref='tag:blogger.com,1999:blog-3650259870998252242.post-1372210369473171347' source='http://www.blogger.com/feeds/3650259870998252242/posts/default/1372210369473171347' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-912368327'/></entry><entry><id>tag:blogger.com,1999:blog-3650259870998252242.post-6920358781115360966</id><published>2009-12-25T01:59:57.969+01:00</published><updated>2009-12-25T01:59:57.969+01:00</updated><title type='text'>@anonymous

Actually, this time IE behaves correct...</title><content type='html'>@anonymous&lt;br /&gt;&lt;br /&gt;Actually, this time IE behaves correctly. Firefox and Chrome are too forgiving for the invalid HTML syntax used in the document.&lt;br /&gt;&lt;br /&gt;If you look closely in the last code snippet in the article the DIV is not closed (first line) so the IFRAME element shouldn&amp;#39;t be interpreted at all. FF/Chrome fix it silently and the iframe gets displayed.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3650259870998252242/1372210369473171347/comments/default/6920358781115360966'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3650259870998252242/1372210369473171347/comments/default/6920358781115360966'/><link rel='alternate' type='text/html' href='http://blog.kotowicz.net/2009/12/new-facebook-clickjagging-attack-in.html?showComment=1261702797969#c6920358781115360966' title=''/><author><name>Krzysztof Kotowicz</name><uri>http://www.blogger.com/profile/11516786094492717236</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.kotowicz.net/2009/12/new-facebook-clickjagging-attack-in.html' ref='tag:blogger.com,1999:blog-3650259870998252242.post-1372210369473171347' source='http://www.blogger.com/feeds/3650259870998252242/posts/default/1372210369473171347' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1270688555'/></entry><entry><id>tag:blogger.com,1999:blog-3650259870998252242.post-3367431174768137762</id><published>2009-12-24T21:28:47.960+01:00</published><updated>2009-12-24T21:28:47.960+01:00</updated><title type='text'>haha wait, it doesn&amp;#39;t work in IE because IE ty...</title><content type='html'>haha wait, it doesn&amp;#39;t work in IE because IE typically does not comply with most regulations? thats a new one lmao</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3650259870998252242/1372210369473171347/comments/default/3367431174768137762'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3650259870998252242/1372210369473171347/comments/default/3367431174768137762'/><link rel='alternate' type='text/html' href='http://blog.kotowicz.net/2009/12/new-facebook-clickjagging-attack-in.html?showComment=1261686527960#c3367431174768137762' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.kotowicz.net/2009/12/new-facebook-clickjagging-attack-in.html' ref='tag:blogger.com,1999:blog-3650259870998252242.post-1372210369473171347' source='http://www.blogger.com/feeds/3650259870998252242/posts/default/1372210369473171347' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1045297389'/></entry><entry><id>tag:blogger.com,1999:blog-3650259870998252242.post-704395171535593467</id><published>2009-12-23T10:09:26.955+01:00</published><updated>2009-12-23T10:09:26.955+01:00</updated><title type='text'>Thanks for great info</title><content type='html'>Thanks for great info</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3650259870998252242/1372210369473171347/comments/default/704395171535593467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3650259870998252242/1372210369473171347/comments/default/704395171535593467'/><link rel='alternate' type='text/html' href='http://blog.kotowicz.net/2009/12/new-facebook-clickjagging-attack-in.html?showComment=1261559366955#c704395171535593467' title=''/><author><name>warrioRR</name><uri>http://www.wasi620.blogspot.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.kotowicz.net/2009/12/new-facebook-clickjagging-attack-in.html' ref='tag:blogger.com,1999:blog-3650259870998252242.post-1372210369473171347' source='http://www.blogger.com/feeds/3650259870998252242/posts/default/1372210369473171347' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1316982154'/></entry><entry><id>tag:blogger.com,1999:blog-3650259870998252242.post-6344922775029079122</id><published>2009-12-23T02:20:43.833+01:00</published><updated>2009-12-23T02:20:43.833+01:00</updated><title type='text'>thanks for the write up</title><content type='html'>thanks for the write up</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3650259870998252242/1372210369473171347/comments/default/6344922775029079122'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3650259870998252242/1372210369473171347/comments/default/6344922775029079122'/><link rel='alternate' type='text/html' href='http://blog.kotowicz.net/2009/12/new-facebook-clickjagging-attack-in.html?showComment=1261531243833#c6344922775029079122' title=''/><author><name>Tom Brennan</name><uri>http://www.blogger.com/profile/17763780984670281558</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://1.bp.blogspot.com/_Bqg1rj8qTPk/Sb6MGC0woMI/AAAAAAAAC1U/d6blUxSfWig/S220/brennan.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.kotowicz.net/2009/12/new-facebook-clickjagging-attack-in.html' ref='tag:blogger.com,1999:blog-3650259870998252242.post-1372210369473171347' source='http://www.blogger.com/feeds/3650259870998252242/posts/default/1372210369473171347' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-982989152'/></entry></feed>
