The security hole I found on Amazon.com
onlineaspect.com
onlineaspect.com
[0]: https://en.wikipedia.org/wiki/Clickjacking#Examples
Edit: This example was added to the wiki page in December 2009. Relevant link: https://en.wikipedia.org/w/index.php?title=Clickjacking&oldi...
(note: amazon could fix this by detecting when opener is xdomain and requiring some minimum number of mouseover events in the page before the button is clickable).
I googled this but found nothing relevant. Do you have a link?
Based on my testing, it appears Rails does not add that header either. Do any other frameworks?
However, it is not turned on by default on old versions (<1.6) I believe, but latest versions should be fine: https://docs.djangoproject.com/en/dev/topics/http/middleware... .
[1]: https://github.com/rails/rails/blob/master/guides/source/sec... [2]: https://github.com/rails/rails/commit/2a290f7f7cdf775491eda0...
So PSA: Updating Rails in an existing app does not cause this header to be added. You must add it yourself in application.rb if it's not already there. See garethadams' footnote #2 above.
http://en.wikipedia.org/wiki/Motivation#Intrinsic_and_extrin...
Yes, I may be a bit bitter...
"Your PHP installation appears to be missing the MySQL extension which is required by WordPress."
That's an old joke and obviously an exaggeration, but it's not horribly far off. Wordpress instances fall to attack constantly, due to a combination of bugs in the base application itself (not terribly common) and extensions (not just common -- CONSTANT). In terms of breakability, I would rank Wordpress in the top 1% of applications without a second thought.
I'm at a loss for words, scaredy-cat.
I was under the impression that a big reason why 0day exploits are not popping up all over is because the folks who discover them can now sell them (for way more than any bounty program), whereas earlier the only way to monetize was to use them as advertisement for selling your skills. Instant payment vs Contractual jobs. I'd say now the 0day vulns end up in the hands of professionals (criminal networks/state actors) rather than script kiddies.
Edit: https://gist.github.com/joshfraser/819308dbae43ff70d892
Sorry, but that's not how Amazon's "Buy It Now" option works. It sends the item to the default address on file. So it would not be possible for the clickjacker to get it mailed to their own address.
https://www.amazon.com/gp/product/B004LLIKVU/gcrnsts?ie=UTF8...