TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

How to cause utter chaos on Facebook

33 点作者 thomasdavis大约 14 年前

6 条评论

program大约 14 年前
It all began when a user pasted the value of the <i>jsText</i> variable in the address bar. The script create a new <i>script</i> DOM element and append it to <i>head</i> injecting the malicious links (so that there is no more need to run the bookmarklet-like link.)<p>The problem here is that the (old) Facebook prompt_page.php page:<p><a href="http://www.facebook.com/connect/prompt_feed.php" rel="nofollow">http://www.facebook.com/connect/prompt_feed.php</a><p>doesn't sanitize feed_info[action_links][0][href] allowing <i>javascript:</i> links.
kooshball大约 14 年前
Can someone post an image of what the "Remove this app" picture actually looks like? does it show as part of the newsfeed?
评论 #2539813 未加载
wilshire461大约 14 年前
It seems as though she is more the victim of some asshole that may or may not know her, that is now trying to extract some revenge by making her life a miserable hell while this mess gets sorted out.
rottyguy大约 14 年前
seems like a better way to cause a dns attack on the file hosters machine no? better title: dns attack from facebook.
thomasdavis大约 14 年前
Makes a vulgar post on a users wall, if the user clicks "Remove this app" it then post it to all your friends walls.<p>Reddits reaction thus far <a href="http://www.reddit.com/r/reddit.com/search?q=nicole+santos" rel="nofollow">http://www.reddit.com/r/reddit.com/search?q=nicole+santos</a><p>Edit: I think facebook has already taken it down, it lasted about 30 minutes.
评论 #2539777 未加载
bhickey大约 14 年前
Great, you found a script injection. However, I think you misunderstand "Hacker News"
评论 #2539854 未加载