logoalt Hacker News

Trick users and bypass warnings – Modern SVG Clickjacking attacks

78 pointsby spartanatreyutoday at 12:03 AM9 commentsview on HN

Comments

autoexectoday at 1:18 AM

I already keep SVG disabled for security reasons, but it's increasingly looking like I'll have to find some way to disable CSS too. It's too bad people couldn't leave CSS alone as a nice simple (sort of) way to format text because turning it into another programing langue is begging for it to be abused by hackers and other malicious actors (like advertisers) just like JS

show 3 replies
paulpaupertoday at 1:43 AM

A long time ago there was a facebook clickjacking method that could make someone inadvertently share a link or like a page. The former required clicking a combination of colored buttons and was quite clever. This was in 2010. But it could not do more, like steal sessions.

zephraphtoday at 2:56 AM

The SVG adder is art. Love it.

scoofytoday at 1:39 AM

As someone who runs a site that uses inline SVG, this is unfortunate. Hopefully it won't be a problem for me.

show 1 reply