3 ms·
> 2) For a long time, there was no frame-breaking script on m.facebook.com. You could clickjack essentially anything on Facebook this way. Years ago I did a pro
by update 10y ago
> 2) For a long time, there was no frame-breaking script on m.facebook.com. You could clickjack essentially anything on Facebook this way. Years ago I did a proof-of-concept on this where I clickjacked a platform app authorization, which let me receive the name, email, and other profile info of any user that did nothing more than click the X button on an annoying overlay I put on the screen.
Do you still have a copy of this? I'd like to see it
- downandout 10y agoToday it wouldn't work because they now have frame-breaking on m.Facebook.com. But if you'd like to see the general template you can email me at the email in my HN profile. Basically, you position the iframe element over something that will be clicked (such as an advertisement X button), set its z-index so that it is the topmost element, and set its opacity to 0. You can even test to see when the click has occurred by testing for when a certain element on your page has lost the focus.
- update 10y ago> Today it wouldn't work because they now have frame-breaking Yeah. I just want to see what the original vulnerability looked like. I bug hunt. Thanks for the offer to email you, but, I'm transitioning away from E-Mail for security reasons.