Shortly before I left Yahoo we implemented clickjacking protection on
del.icio.us, in response to the attack on Twitter, documented here:

http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=213000919

... and PoC'd here:

http://qd9.co.uk/temp/ClickJackEg.html

While I shouldn't talk about what was done for del.icio.us, one way to
go after clickjacking might be to dynamically generate the Submit
button using JavaScript.

--Kent
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"OAuth" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [email protected]
For more options, visit this group at http://groups.google.com/group/oauth?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to