Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
User Journal

Journal gbulmash's Journal: CSS Trick Hijacks MySpace Pages, Blogs

I got a MySpace friend request this morning. When I clicked over to the person's page, I found that clicking just about anywhere on it sent me to a porn site. Looking at the source, I found that this was accomplished through a simple piece of CSS. Wondering how effective it was, I tried it on my Akismet-protected blog and another and was able to hijack the pages. Seems that anywhere that you allow people to put HTML tags in a comment, unless you're filtering for this, they may be able to hijack the page where the comment is displayed.
This discussion has been archived. No new comments can be posted.

CSS Trick Hijacks MySpace Pages, Blogs

Comments Filter:

It is clear that the individual who persecutes a man, his brother, because he is not of the same opinion, is a monster. - Voltaire

Working...