Per the video showing the exploit: I thought since it was being served through an iFrame, it won't allow you to effect the inner elements with CSS/JS? If that doesn't matter, is there a way that Facebook, Twitter, Google+, etc. can do anything on their end so the front end user (or exploiter, in this case) can't modify the button with CSS to do these types of things?