Sign up Login
home | you | technology | web 2.0 | podcasts | entertainment | photos | comics | videos
 
Latest from Neil Mix
 

FBJS Beta Security Hole #3

Thursday, August 9, 2007

Today’s exploit uses the same constructor-climbing technique as yesterday’s exploit, but explores a different avenue of attack: direct DOM access. FBJS does an excellent job of properly scoping objects so that the only access points to the DOM are the ones they provide you. For example, let’s say I grab an FBJS-wrapped DOM element:

  var div = document.getElementById("myElement");

This gets re...


Original article from http://www.neilmix.com/2007/08/08/fbjs-beta-security-hole-3/
Login to read full articles and enjoy our free features for members.
« Facebook Security Hole #2
Henry “Speaks” »
 

Related articles