Earlier quoted context omitted.
> 2) For a long time, there was no frame-breaking script on m.facebook.com. You could clickjack essentially anything on Facebook this way. Years ago I did a proof-of-concept on this where I clickjacked a platform app authorization, which let me receive the name, email, and other profile info of any user that did nothing more than click the X button on an annoying overlay I put on the screen. Do you still have a copy…
Today it wouldn't work because they now have frame-breaking on m.Facebook.com. But if you'd like to see the general template you can email me at the email in my HN profile. Basically, you position the iframe element over something that will be clicked (such as an advertisement X button), set its z-index so that it is the topmost element, and set its opacity to 0. You can even test to see when the click has occurred b…
Yeah. I just want to see what the original vulnerability looked like.
I bug hunt.
Thanks for the offer to email you, but, I'm transitioning away from E-Mail for security reasons.