Ingenious Hack by Facebook Spammers: Smoking Hot Bartenders
liquidrhymes.com
liquidrhymes.com
It's not really ingenious. It's just scammy behavior and yet another fine reason to run NoScript.
It'd be better for browser makers to simply detect clickjacking and block it.
If an element isn't visible to the user (either partially visible or behind other elements), that's probably a good sign it shouldn't be able to receive user actions such as clicks. Especially if it's an iframe.
I hope firefox+chrome do some work on this soon.
It's amazing how quickly 'click one button to be able to view this website' would irritate the hell out of anyone.
It's certainly an option for geeks or security freakouts, but not really an option for normal people.
Also how would a 'normal' person decide if a website is 'safe' to enable js or not? If you're the kind of person fooled into clicking for 'hot bartenders' and filling out a survey to get access, you're probably not able to decide if you should enable js or not.
The solution isn't to shift responsibility to users, it's to fix the browser flaws that allow clickjacking to happen.
The example given here should be a textbook easy to fix bug in browsers. It's a browser issue which should be high priority.
An iframe which isn't visible to the user, should not be able to receive input from the user.
You can't really just cop-out that if something is open source then it's not fair game for criticism. Firefox has some big bugs open for months before they get worked on.
To prevent the example cited from working would likely take 10-20 lines of code in webkit/firefox. But it'd likely take a week or so to get up to speed with the project to be able to know where to insert those lines of code. Fixing other methods of hiding an iframe would likely take a bit more thought, but it's hardly rocket science.
I have enough to do without fixing browsers ;)
I have enough to do without fixing browsers.
You explained your own observation.
You can't really just cop-out that if something is open source then it's not fair game for criticism.
Open Source is certainly "fair game for criticism". But you aren't going to get anything out of criticism, because criticism cannot write any code. Open Source is all about people seeing a problem, fixing the problem, and sharing the fix. Nothing more. And it certainly has no obligation to a user who is quick to criticize but slow to fix.
It's the software engineering equivalent of yelling at the TV when the news makes you mad. It's pointless and makes you look insane.
For me, it'd likely be a week to get up to speed with the project. So it's more efficient for me, and other users not familiar with the codebase to yell at the developers for a day or two and see if they'll fix it.
I know in open source utopia everyone seamlessly just hops into other projects, fixes a bug, says 'here you go! bye for now', and carries on to the next project, but that doesn't happen in real life.
Who knows though, maybe I'm wrong. Maybe there's a really good reason they allow clickjacking. But I certainly can't see one.
Back when I experimented with manually authorizing cookies on all websites I visited, it was surprising how quickly the number of cookie prompts dropped to near-zero. There really aren't that many websites that you visit.
Also I notice you say "Back when I experimented.." -- was there a reason it didn't work out in the end?
I don't know how good the click-jacking or XSS protection is. For me it has always been a false positive, and usually very quickly fixed and ack'ed in the changelog, and otherwise, I really don't browse the web in such a way that I'm routinely encountering such things. (Plus I do use it with scripting off, so anything like a malicious script to further trigger an XSS elsewhere won't work on me.)
But even if you don't want the script blocking, it can be useful.
(And as others have observed, it is less annoying that you might initially guesstimate. I use it on two machines with no configuration sync'ing, and it still isn't annoying to me.)
I have done this to myself, incidentally, because I did not believe the doc tha said it was possible.
If you include Open Graph tags on your Web page, your page becomes equivalent to a Facebook page. This means when a user clicks a Like button on your page, a connection is made between your page and the user. Your page will appear in the "Likes and Interests" section of the user's profile, and you have the ability to publish updates to the user. Your page will show up in same places that Facebook pages show up around the site (e.g. search), and you can target ads to people who like your content.
This means either cutting your friends out of your private data, selecting your friends based on their computer savvy, or being as vulnerable as the most insecure of them.
I say again: Facebook is the devil. It's a brilliant platform that should continue to grow for years. It uses your own friends to make you do things you would not normally do (like join). As a platform it has no other goal than total domination of the net.
Only a matter of time before that gets clickjacked though.
Most don't understand this. It's a royal pain. Read through this article by PJF, "Facebook privacy - Instant personalisation and connections" ~ http://pjf.id.au/blog/?position=604
If thats true it really needs to be better communicated by Facebook.
javascript:(function(){try{var%20url=encodeURIComponent(location.href);var%20ifr=document.createElement('iframe');ifr.style.position='absolute';ifr.style.top=10+'px';ifr.style.left=10+'px';ifr.style.width=450+'px';ifr.style.height=100+'px';ifr.style.border='none';ifr.src='http://www.facebook.com/plugins/like.php?href='+url+'&show_faces=true&width=450&action=like&colorscheme=light';ifr.scrolling='no';ifr.frameborder=0;document.getElementsByTagName('body')[0].appendChild(ifr);}catch(e){}})();
Then you can visit any webpage and "like" it.Correct me if I'm wrong.
Mouse-over the big freaking div, click on the little cross on its top right, and choose "Hide FarmVille" or "Hide Mafia Wars" or "Hide Doomaflotchie Widget", and you'll never see any updates from the damn thing again. Across computers. Which makes it better than Greasemonkey scripts or browser addons.
I'm sure that plenty of people couldn't care less, but I think it's a creepy thing.
Of course the whole point of the Facebook "Like" button is to be embedded on other websites, so frame busting is out of the question. I'm not sure if there's a quick fix for this. Browsers need to disallow clicking of transparent iframes.
As a Chrome user on Linux, and a pretty much lifelong user of Linux on the desktop, I am rather unaccustomed to being the victim of such exploits, so I didn't immediately know what to do. This one appears to be purely browser/JS-based and/or perhaps exploits some weakness in the Facebook API.
It started when a (presumably "infected") friend of mine posted on my wall. It looked to be just text, but presumably contained a trigger for this exploit. Anyway, within seconds, somehow, unbeknownst to me, I was apparently initiating chat conversations with every friend who was online "asking," "Do you have a second?" When they would reply "yes?", I would blast them with some bullshit quiz/test site link, which I can only assume is a phishing farm.
Anyway, this continued relentlessly so long as I was logged into the site (and possibly when I wasn't, never definitively established that) until it occurred to me to change my Facebook account password, after which it - knock on wood - seems to have stopped.
Does anyone have any idea how this exploit works? It caught me rather off-guard because I expected that sort of thing to be the work of viruses and/or malware on Windows. I would guess that my password was somehow phished out, after which some foreign agent logged into the Facebook messenger as me externally (quite possible to do, numerous IM clients now support the Facebook messenger protocol) and went nuts, but I can't be sure.
Other than keeping your browser logged out of facebook at all times, what's the protection against this?
Another option might be for Facebook to ban likes on a domain basis. If a domain is using spammy techniques like this then ban it from being liked by anyone. Of course that means more overhead and moderation.
I don't think there is a good solution to this, only work arounds.
The easiest fix to the spreading of this issue is FB not broadcasting every single time you like something... but they're not gonna do that, we already know. So, the spam will continue.
For example...
window.confirm = function(m) { return true; }
Actaully... I started writing that as a joke but now that I think about it, if the browser embedded the opacity value of the clicked element in the GET or POST header, the webserver receiving the click could set the standard themselves.
Alternately, since facebook has lots of resources, facebook could make a request to the referring site themselves, render the page and determine if there are any shenanigans going on with z-ordering or opacity automatically. You could look at all of the css applied to all of the element affecting those pixels.
No... this is all crazy. Just pick a value like 30% and disallow clicks on anything less.
What about background: transparent?
What about background: url(transparent.png)?
What about background: data:encoded-transparent-image...
Even browser-side "visibility" calculations can become an AI-level problem quickly.
Anything not proven visible counts as invisible. Done!
Well, you could open these links in an Incognito window which doesn't have access to your Facebook cookies.
Obviously this solution doesn't scale to normal users.
This would appear to be (among?) the first malicious use of the like-jacking vulnerability.
But I was protected due to the ever useful Adblock extension. Probably the best plugin out there, the easiest method to fire and forget about annoying web elements.