<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; clickjacking</title>
	<atom:link href="http://hackaday.com/tag/clickjacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 12:56:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; clickjacking</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>Curiosity killed the twit, Twitter clickjacking</title>
		<link>http://hackaday.com/2009/02/12/curiosity-killed-the-twit-twitter-clickjacking/</link>
		<comments>http://hackaday.com/2009/02/12/curiosity-killed-the-twit-twitter-clickjacking/#comments</comments>
		<pubDate>Thu, 12 Feb 2009 20:08:26 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[clickjacking]]></category>
		<category><![CDATA[don't click]]></category>
		<category><![CDATA[iframe]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[snippet]]></category>
		<category><![CDATA[tinyurl]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[twitter.com]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=8481</guid>
		<description><![CDATA[Twitter was flooded this morning with users posting &#8220;Don&#8217;t Click: http://tinyurl.com/amgzs6&#8243;. TinyURL has since terminated the URL. The original page doesn&#8217;t seem to be live either. It displayed a button that said &#8220;Don&#8217;t Click&#8221;. If the user happened to be logged into Twitter, it would automatically update their status. The instigator partially describes the method [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=8481&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-8482" title="dontclick" src="http://hackadaycom.files.wordpress.com/2009/02/dontclick.jpg" alt="dontclick" width="450" height="172" /></p>
<p>Twitter was flooded this morning with users posting &#8220;Don&#8217;t Click: http://tinyurl.com/amgzs6&#8243;. TinyURL has since <a title="TinyURL.com - where tiny is better!" href="http://tinyurl.com/nospam.php?id=amgzs6">terminated the URL</a>. The <a href="http://www.umoor.eu/blog/yes-we-can.php">original page</a> doesn&#8217;t seem to be live either. It displayed a button that said &#8220;Don&#8217;t Click&#8221;. If the user happened to be logged into Twitter, it would automatically update their status. The instigator partially describes the method <a title="-) | Korben" href="http://www.korben.info/petit-cours-de-twitt-jacking.html">on his blog</a> (<a title="Google Translate" href="http://translate.google.com/translate?prev=_t&amp;hl=en&amp;ie=UTF-8&amp;u=http%3A%2F%2Fwww.korben.info%2Fpetit-cours-de-twitt-jacking.html&amp;sl=fr&amp;tl=en&amp;history_state0=">translated</a>). The page would load the user&#8217;s Twitter page in an invisible iframe. The status would be pasted in and the &#8220;Don&#8217;t Click&#8221; button is placed on top of the update button. You can find the <a title="How to Get People to Tweet for You Without Them Knowing - Raven SEO Tools" href="http://raven-seo-tools.com/blog/310/evil-genius-how-to-get-people-to-tweet-for-you-without-them-knowing">code snippets here</a> and the original author <a title="Clickjacking Twitter - James Padolsey" href="http://james.padolsey.com/general/clickjacking-twitter/">credits this post</a> for the inspiration. Twitter has since <a title="Clickjacking Twitter - James Padolsey" href="http://james.padolsey.com/general/clickjacking-twitter/#comment-5095">added a JavaScript fragment</a> to each page to break out of iframes.</p>
<p><pre class="brush: jscript;">if (window.top !== window.self) { window.top.location.href = window.self.location.href; }</pre></p>
<br />Posted in news, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/8481/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/8481/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/8481/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/8481/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/8481/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/8481/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/8481/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/8481/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/8481/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/8481/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/8481/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/8481/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/8481/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/8481/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=8481&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/02/12/curiosity-killed-the-twit-twitter-clickjacking/feed/</wfw:commentRss>
		<slash:comments>24</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/02/dontclick.jpg" medium="image">
			<media:title type="html">dontclick</media:title>
		</media:content>
	</item>
		<item>
		<title>Clickjacking webcast tomorrow</title>
		<link>http://hackaday.com/2008/11/19/clickjacking-webcast-tomorrow/</link>
		<comments>http://hackaday.com/2008/11/19/clickjacking-webcast-tomorrow/#comments</comments>
		<pubDate>Wed, 19 Nov 2008 22:20:32 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[clickjacking]]></category>
		<category><![CDATA[eric lawrence]]></category>
		<category><![CDATA[jeremiah grossman]]></category>
		<category><![CDATA[webcast]]></category>

		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=6068</guid>
		<description><![CDATA[[Jeremiah Grossman] and [Eric Lawrence] will be presenting on clickjacking and browser security in an online seminar tomorrow. Clickjacking allows an attacker to transparently place links exactly where a user would be clicking, essentially forcing the user to perform actions without their knowledge. This method of attack has been known for a few years, but [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=6068&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img src="http://hackadaycom.files.wordpress.com/2008/08/had-fuzzing-v-statcodeanalysis.jpg?w=450&#038;h=159" border="0" alt="" hspace="4" vspace="4" width="450" height="159" /></p>
<p>[Jeremiah Grossman] and [Eric Lawrence] will be presenting on clickjacking and browser security <a href="https://event.on24.com/eventRegistration/EventLobbyServlet?target=registration.jsp&amp;eventid=122494">in an online seminar tomorrow</a>. Clickjacking allows an attacker to transparently place links exactly where a user would be clicking, essentially forcing the user to perform actions without their knowledge. This method of attack has been known for a few years, but researchers have focused their attention on it lately because they feel the threat has been underestimated. Recently, Adobe patched a vulnerability specifically because of this issue. Tune in tomorrow for more info on the attack.</p>
<br />Posted in news, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/6068/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/6068/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/6068/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/6068/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/6068/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/6068/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/6068/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/6068/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/6068/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/6068/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/6068/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/6068/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/6068/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/6068/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=6068&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/11/19/clickjacking-webcast-tomorrow/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/08/had-fuzzing-v-statcodeanalysis.jpg" medium="image" />
	</item>
	</channel>
</rss>
