Cursor:none abuse (trick users into clicking Facebook 'like')
jack-shepherd.co.uk
jack-shepherd.co.uk
Edit: It seems like this is a largely solved problem for Facebook: http://forum.developers.facebook.net/viewtopic.php?id=93201&...
Could definitely still be a problem for other social/ad/affiliate networks though.
This makes attacks such as these a little less worrying.
Most people will click just to see what it might be and not miss out. Then the video player says you have to click on some letters to prove you're not a robot (clever trick, people don't think much of it because it reminds them of CAPTCHAs)
The letters actually have Facebook Like button iframes on them with opacity set to 0. I edited the opacity on one of them with the Chrome Dev tools:
http://polyprograms.free.fr/tmp/FacebookLikeClickJacking.jpg
Unknowningly liking the video will create a story in your friends' feeds, who will in turn click to see and spread it to their friends. No real harm is done except for the spam and all the ad views generated.
pointer-events: none on an opaque container, with the FB 'like' button below it.
And, even in the mode where JavaScript is allowed by default on new sites, the other protections (Clickjacking, XSS, ABE, etc) still apply.
Many people (including myself) would swear by leaving the cookie notification on and confirming every. single. one. of. them.
That has long stopped being feasible and I assume it will be the same with NoScript in a few years.
Also, stuff like this is why we can't have nice things in browsers. You can't trust the internet.
Javascript makes a lot of cool stuff possible, but outside of some heavy-weight web applications that I have to trust anyway like my webmail interface or online storage manager, or games where the interactive components are the only reason why I'm visiting the site to begin with, I'm starting to wonder whether trusting the internet is not inviting more trouble than it's worth.
Maybe I'm "old-fashioned" but I'd love to go back to all the sites I visit functioning with just static web content, no clientside scripting at all, and letting me consume videos and stuff in a trusted media player plugin.
HTML5 generally solves this with <audio> and <video>. If implemented correctly by browsers, they should not require any scripting on the site itself to work.
That said, "trusted" media player plugins (think Flash) have been the targets of many successful attacks as well.
I'm thinking a dumb unscriptable video playback frame that draws its own controls and isn't remote-controlled by javascript.
I've seen plenty of sites that see that see I don't have javascript enabled (or unblocked) and conclude that welp, that guy probably doesn't have speakers, let's display a unhelpful message instead of embedding media content.
Of course there'll still be some attack surface just like people have been managing to exploit image decoding libraries over the years, but at least it wouldn't be engineered against usability by default.
More and more of the applications we use and our private data live in the cloud. We now access our personal files, manage our bank and investment accounts, and make retail purchases on our web browser.
Browsing the web with JavaScript enabled by default allows code written by complete strangers to run on your browser!
There have been various vulnerabilities (especially in IE) but just like any other software they get fixed.
Leave aside the various vulnerabilities (including cross-site-scripting ones!) that get discovered with disturbing frequency, and please consider the subject of this thread: it's possible to make someone click a "Like" button without their realizing it! How many other similar tricks can JavaScript be used for by people with nefarious intentions?
No matter how "safe" any runtime environment is, allowing strangers to execute arbitrary code on your computer is never a great idea.
This is why I allow JavaScript code to run on my browser only when it comes from sources I trust.
EDIT: Why am I being downvoted for this question? I am seriously interested, so that I can avoid contact with them.
{+block{Facebook "like" and similar tracking URLs.}} www.facebook.com/(extern|plugins)/(login_status|like(box)?|activity|fan)\.php
{+block{Stupid facebook xd_proxy.php.}} http://static.ak.fbcdn.net/connect/xd_proxy.php.*
The second one also removes an annoyance I see from time to time when I bypass the proxy which makes the page request again and again that xd_proxy.php file.
If I really want to like something, I disable the proxy and reload the page. I use Proxy SwitchySharp (2) for chrome to do the setup for me in pages I visit often.
1: http://www.privoxy.org/ 2: https://chrome.google.com/webstore/detail/dpplabbmogkhghncfb...
I've blacklisted all ad networks from executing and JavaScript but I maintain a strict whitelist which means that sites such as Facebook, Google, and any site which I browse and immediately see is broken is added to my whitelist.
When I browse a page, I can have conditional execution of the JS code, meaning that JS from 3 domains will run, but the 9 tracking JS code from all the ad networks won't run.
It's like the best of all worlds. Adnetworks can't fingerprint me, and they have to rely on cookies, plus my browsing is a hell of a lot faster because I don't have all the unneccessary JS downloading and running.
I admit the thought that some users aren't using JS concerns me because, while I try and always build sites with a fallback, it generally results in a lesser experience. Often fallbacks just aren't possible so I need to remove the feature altogether.
I bet there's a lot of sites that still work for you, but not quite as well as if JS were enabled.
Make your content load, but anything above that, users are on their own if they decide not to enable JavaScript.
In this age, with all of the rich user applications, JS is practically a requirement.
For my startup, the frontend gracefully fallbacks to a working version for users.
For the backend, they get a blackscreen saying JS is required. If users are going to use my application, they should expect to have JS enabled for the best possible user experience.
Don't worry about it is the upshot!
In fact, even if you can't change the cursor at all, you could easily create a swarm of fake cursors that would frustrate the hell out of the user.
If you give an id (or class) to your p tag that contains the links you said you wanted to make easier to click, then you could use css and easily add a :hover state. Then on the hover state just make the cursor normal so it's easier to click those links. Upon mouseout the cursor will go back to 'normal'. =)
The site is still able to disable my mouse over most of the screen.
Am I the only one?