Simon Willison’s Weblog

Subscribe
Atom feed for theharmonyguy

1 item tagged “theharmonyguy”

2009

The Dangers of Clickjacking with Facebook. theharmonyguy compiled a list of actions that can be triggered on Facebook by a single click, and hence are vulnerable to clickjacking attacks. The list includes authorising malicious applications, posting links to profiles, sending friend requests and sending messages to other users. Why don’t Facebook include frame busting JavaScript on every page?

# 23rd December 2009, 10:20 am / clickjacking, facebook, framebusting, phishing, security, theharmonyguy