Collected research
Hacking Facebook with HTML5
touch.facebook.com read the URL fragment and fetched it by AJAX into a div, and CORS made the request cross-origin instead of an error. Loading a PHP page that returns Access-Control-Allow-Origin: * injects an img onerror payload into Facebook's mobile interface from a hidden iframe, then document.domain widens it to facebook.com. Fixed within a day.
Record
- Researcher
- matt
- Published by
- m-austin.com
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of matt, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .