http://images.google.com/imgres?imgurl=http://www.internet.c...
THe page just displays a "you are being redirected" message straight away, so it must be detected at the server level. Smart.
http://images.google.com/imgres?imgurl=http://a1.twimg.com/p...
google doesn't detect or stop that breaking out of frames. But maybe twitter are just managing to avoid detection by google's code..
The code on that page is:
<script type="text/javascript">
//<![CDATA[
if (window.top !== window.self) {document.write = "";window.top.location = window.self.location; setTimeout(function(){document.body.innerHTML='';},1);window.self.onload=function(evt){document.body.innerHTML='';};}
//]]>
</script>
which doesn't seem like it would be too hard to detect.Replacing 'top.location' with 'self.location' probably does the trick for 95% of sites.
If you look at the bottom of ui.js, you can see I tried a brute-force framebuster-buster. It does notify the user that the site is trying to break out, but it also catches legitimate outgoing links. It needs to be polished more before I can release it.
This is issue #1 on github for the project, BTW.