Simon Willison’s Weblog

Items tagged javascript, framebusting, gadgets, phishing

Filters: javascript × framebusting × gadgets × phishing ×


Frame-Busting Gadgets. I’ve always been slightly suspicious of the Google Gadgets / OpenSocial idea of sandboxing untrusted third party content in an iframe. Sure enough, it turns out iframe busting scripts work in Gadgets, meaning a seemingly harmless gadget could potentially launch a phishing attack. # 17th September 2008, 11:23 pm