Vimeo highly vulnerable to CSRF attacks – now fixed
I recently found, that vimeo.com had a cross-domain policy, that allowed anyone to connect, which was an open invitation for CSRF attacks. I alerted them to the issue, and it has now been fixed.
My life with ActionScript, JavaScript and their families
I recently found, that vimeo.com had a cross-domain policy, that allowed anyone to connect, which was an open invitation for CSRF attacks. I alerted them to the issue, and it has now been fixed.
The twenty-seventh idea for my 365 social ideas is an idea which has spun off my “investigation” of the SnapABug service: create a bookmarklet, that when clicked let’s you mark a section of the current webpage you are viewing (in it’s current state etc.) and then snapshots this and uploads the image to your image sharing service of choice – popular choices being flickr or more shoot-from-the-hip style services like tinypic.
The twenty-third idea for my 365 social ideas is a very simple one: Wrap a Safari browser in a Mac OS X application that opens on Google Docs as the first (and only) website you can see.
The twenty-second idea for my 365 social ideas is not really a clear-cut idea – yet. But I feel a need for a new website traffic analyzing service. Google Analytics is definitely the mostly used and best free service. But they have many shortcomings, and I definitely would like to see a new player enter this playing field. And while where add it, there are some new trends and actions, that current has a huge influence on current traffic trends, that you cannot track fully: social media traffic.
The twenty-first idea for my 365 social ideas is another gaming idea: create a set of classic flash-based games along the lines of break-out, tetris etc, but integrate a simple storyline with good and bad characters, places and items involved and make these configurable. You could through this create a game of your own life by inserting persons from your surroundings, places where you meet, stuff that you work with etc. and you could send this game to your friends and family and they could then play out the big game of your life.
The sixteenth idea for my 365 social ideas is an idea for a technical tool to assist everyone in getting the credit they deserve and the loyalty they can expect: a copy-paste injection script. It is the very same idea that tynt.com has “created”, but they keep the technology (how simple it may be) to themselves and have even filed for a patent.
1 comment » | DOM 2 Traversal and Range, HTML, January 2010 Ideas, Online Rights, Trends, jQuery
The fourteenth idea for my 365 social ideas is a somewhat silly little gadget website idea, but none-the-less an idea, that I would like to share with you all: a service, that tells you when it is your next round birthday in all time units, that you could think of. Why did I come up with this idea, you might ask? Because I some time ago found out, that I missed my 10,000 birthday (that is the 10,000th day since my birth), which occurs when you are 27 years and 138 days (or 139 days depending on leap years).
The second idea for my 365 social ideas is news aggregation-based as well as usability-oriented. The idea is a cross between the fascinatingly simple Readability bookmarklet and the recently launched Danish online newspaper “Ugen” (Eng: “The Week”), which is a downloadable AIR-application for news reading.
We got the XKCD book “volume 0″ here at work yesterday, and I have of course skimmed through it many times already. I quickly found the solution to the page numbering scheme, but wanted to see if I could find a simple conversion formula from real number to XKCD page number and vice versa.
I just saw a link on Facebook, that I somehow had to interact with – it featured a not-that-dressed girl and said “Wanna C Something Hot?”/”Want 2 C Something Hot?” or variations of this. Well, clicking the link sent to me to an external site featuring a single button and the same image urging me to click it. When clicked, I came to some porn site. But why would several of my friends post links to this site, which incidentally sent me to a porn site? Well, as I soon after saw on Facebook, I had just posted the same link on my wall for all my friends to see. How?
It is a “simple” case of “click-jacking” and the site tricks you to click a Facebook share button, but disguises this as some other button. Please read on for full description.
UPDATE 2009-12-2: “Press the button or dog dies”/”Push the button or this dog dies” (located at pressthebuttonordogdies.com, but don’t go there) is a new such site. The target website is “thisblogrules.com” and the measures used are a little different but all in all the same anyway.
Furthermore, I have used bit.ly for tracking how much these links have been used so far on Facebook – it is pretty inflicting: The “hot” girl has been shared almost 59,000 times and the poor dog has been shared 5,309 times as of this writing. You can see the direct stats from the Facebook link.getStats API here: Somthing Hot and Or Dog Dies