Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
The Facebook "Osama Dead" Worm (67.23.246.232)
2 points by makmanalp on May 4, 2011 | hide | past | favorite | 1 comment



The actual link to the facebook page this spreads from is here:

http://www.facebook.com/pages/Osama-is-Dead-Watch-the-Video/...

Apparently people do actually copy the javascript and paste it into the URL bar, effectively getting past cross-domain xhr restrictions.

This looks like another interesting case of "why johnny can't notice security risks". How does one mitigate something like this other than expecting users to be knowledgeable?




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: