514 karma · joined April 2, 2013
Doesn't seem like that is the case here. The bug is in the search form, which is POST only. It wouldn't be enough to share the link to the search page, you'd need something that does the search on your behalf.
Once the form has been submitted on behalf of the user, you have javascript execution in the context of paypal.com, and can do pretty much anything. Send the contents of your account to another address, shut down the account, exfiltrate past transaction data, etc.
Edit: I would appreciate it if someone told me what I said was incorrect or wrong in anyway.
(It's a "love hotel", one character away from a regular hotel, 🏨)
http://www.boston.com/news/local/articles/2008/03/18/rush_ho...
Something from a few years back; I wouldn't be surprised if these photos end up causing even more trouble.
From what it seems, the only thing they take seriously is responding to incidents like these and letting customers know. If they were actually serious about security, these things wouldn't be happening. It was almost over a year ago since the last event.
It would be an interesting experiment to sneak a harmless command after every snippet on a site like commandlinefu.com.
Edit: Also while playing around, I remembered irssi actually has a defense against this. If you try pasting multiple lines, it can detect this. It presents you with a prompt asking if you really intended to paste >5 lines into the text field. I wonder if something like this could be implemented in a shell?
Luckily, this one is still a draft...
I think this is the best point in your argument. If you're going to half-assedly block framing (via JS, not using XFO), you will have problems. Either through sandboxed frames, or using XSSAuditor against it, it will break.
Besides this minor issue, there really is no other serious flaw with sandbox framing.
http://media.blackhat.com/bh-ad-11/Lundeen/bh-ad-11-Lundeen-...
These guys used html5 sandbox to break facebook's javascript frame breaker. Two years ago.