3 ms·
It all began when a user pasted the value of the jsText variable in the address bar. The script create a new script DOM element and append it to head injecting
by program 15y ago
It all began when a user pasted the value of the jsText variable in the address bar. The script create a new script DOM element and append it to head injecting the malicious links (so that there is no more need to run the bookmarklet-like link.)
The problem here is that the (old) Facebook prompt_page.php page:
http://www.facebook.com/connect/prompt_feed.php http://www.facebook.com/connect/prompt_feed.php
doesn't sanitize feed_info[action_links][0][href] allowing javascript: links.