3 ms·
This uses iframes to pit websites against each other. Twitter breaks out of iframes and so do other websites.
by poundy 16y ago
This uses iframes to pit websites against each other. Twitter breaks out of iframes and so do other websites.
- marknutter 16y agoAny idea how to prevent this from happening? Google seems to have figured it out in their google images iframes, but I can't for the life of me figure out how they did it.
- user24 16y agoIt looks like google parse the page serverside to detect break out of frames scripts. Here's a manually engineered example - I searched for a demo of a break out of frames script and forced the URL into a google images request: http://images.google.com/imgres?imgurl=http://www.internet.com/icom_includes/footers/img/icom_logo_qsfooter.png&imgrefurl=http://javascript.internet.com/navigation/manual-frame-break-demo.html&usg=__nA7P9hJ3tihz2fLto_VlTZ96K2M=&h=891&w=883&sz=234&hl=en&start=1&itbs=1&tbnid=IYlLzX-w4vX2AM:&tbnh=146&tbnw=145&prev=/images%3Fq%3Dfoo%26hl%3Den%26gbv%3D2%26tbs%3Disch:1 http://images.google.com/imgres?imgurl=http://www.internet.c... THe page just displays a "you are being redirected" message straight away, so it must be detected at the server level. Smart.
- user24 16y agoHaving said that, if you look at a genuine result from twitter: http://images.google.com/imgres?imgurl=http://a1.twimg.com/profile_images/108462666/home_sscredits_bigger.jpg&imgrefurl=http://twitter.com/homeproject&usg=__gzb2ICTasTI-R6GrhHpOIfNxoVs=&h=3780&w=2835&sz=442&hl=en&start=1&itbs=1&tbnid=_uftMx2399b4tM:&tbnh=150&tbnw=113&prev=/images%3Fq%3Dsite:twitter.com%26hl%3Den%26gbv%3D2%26tbs%3Disch:1 http://images.google.com/imgres?imgurl=http://a1.twimg.com/p... google doesn't detect or stop that breaking out of frames. But maybe twitter are just managing to avoid detection by google's code.. The code on that page is: <script type="text/javascript"> //<![CDATA[ if (window.top !== window.self) {document.write = "";window.top.location = window.self.location; setTimeout(function(){document.body.innerHTML='';},1);window.self.onload=function(evt){document.body.innerHTML='';};} //]]> </script> which doesn't seem like it would be too hard to detect.
- jasonkester 16y agoThe brute-force way to do it is to run a proxy on your own server that loads the page in question, strips out either some or all of the javascript, then serves it onward. Replacing 'top.location' with 'self.location' probably does the trick for 95% of sites.
- onecreativenerd 16y agoAh, but that might skew the results... maybe not too much, though since it's only manipulating the root document? However, cross-domain permission would be broken for javascript inside the site. If you look at the bottom of ui.js, you can see I tried a brute-force framebuster-buster. It does notify the user that the site is trying to break out, but it also catches legitimate outgoing links. It needs to be polished more before I can release it. This is issue #1 on github for the project, BTW.