<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" 
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:wfw="http://wellformedweb.org/CommentAPI/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:meneame="http://meneame.net/faq-es.php"
 >
<channel>
	<title>Menéame: comentarios [484684]</title>
	<link>http://www.meneame.net</link>
	<image><title>www.meneame.net</title><link>http://www.meneame.net</link><url>http://cdn.mnmstatic.net/img/mnm/eli-rss.png</url></image>
	<description>Sitio colaborativo de publicación y comunicación entre blogs</description>
	<pubDate>Mon, 29 Sep 2008 00:26:04 +0000</pubDate>
	<generator>http://blog.meneame.net/</generator>
	<language>es</language>
	<item>
		<meneame:comment_id>2776500</meneame:comment_id>
		<meneame:link_id>484684</meneame:link_id>
		<meneame:order>9</meneame:order>
		<meneame:user>ApolloXXX</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>7</meneame:karma>
		<meneame:url>https://www.meneame.net/story/clickjacking-un-secreto-voces</meneame:url>
		<title>#9 Clickjacking: ¿un secreto a voces?</title>
		<link>https://www.meneame.net/story/clickjacking-un-secreto-voces/c09#c-9</link>
		<pubDate>Mon, 29 Sep 2008 00:26:04 +0000</pubDate>
		<dc:creator>ApolloXXX</dc:creator>
		<guid>https://www.meneame.net/story/clickjacking-un-secreto-voces/c09#c-9</guid>
		<description><![CDATA[<p>La vulnerabilidad afecta a los plugins en concreto uno muy estándar para todos los navegadores (el de Adobe) por eso se recomienda Lynx (que no usa plugins) para navegar seguros <img data-src="https://cdn.mnmstatic.net/v_149/img/menemojis/36/grin.png" alt=":-D" title=":-D" width="18" height="18" src="https://cdn.mnmstatic.net/v_149/img/g.gif" class="emoji lazy" /><br />
<br />
Lo que hace esta vulnerabilidad es sencillo, tu vas a la web X y ves un enlace que pone... Pulsa aqui para ayudar a los niños del Africa, miras la URL y te redirige a una ONG de ayuda a Africa muy conocida, por tanto es de &#34;fiar&#34;<br />
<br />
Cuando haces click, entra en accion la vulnerabilidad, y aprovechan para mandarte a la página B que contienen enlaces maliciosos, que pueden robarte desde cookies, o aprovechar alguna vulnerabilidad del Navegador, al mismo tiempo que al final te redirigen a la página de Africa para que no sospeches.<br />
<br />
No es algo que se pueda hacer igual con IFRAMES, ya que con un vistazo al código ves el iframe y descubres el pastel. Esto segun parece es algo más sutil, y por tanto dificil de parchear.</p><p>&#187;&nbsp;autor: <strong>ApolloXXX</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>2768724</meneame:comment_id>
		<meneame:link_id>484684</meneame:link_id>
		<meneame:order>8</meneame:order>
		<meneame:user>--23321--</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>8</meneame:karma>
		<meneame:url>https://www.meneame.net/story/clickjacking-un-secreto-voces</meneame:url>
		<title>#8 Clickjacking: ¿un secreto a voces?</title>
		<link>https://www.meneame.net/story/clickjacking-un-secreto-voces/c08#c-8</link>
		<pubDate>Sat, 27 Sep 2008 10:18:42 +0000</pubDate>
		<dc:creator>--23321--</dc:creator>
		<guid>https://www.meneame.net/story/clickjacking-un-secreto-voces/c08#c-8</guid>
		<description><![CDATA[<p>No entiendo donde está vulnerabilidad, que diferencia hay entre esto, y cargar la url de destino en un iframe invisible? ambos producen lo mismo: un GET/POST a la url que el dueño de la página quiera.<br />
<br />
Quizá hay algo que no estoy teniendo en cuenta...</p><p>&#187;&nbsp;autor: <strong>--23321--</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>2767510</meneame:comment_id>
		<meneame:link_id>484684</meneame:link_id>
		<meneame:order>7</meneame:order>
		<meneame:user>selvatgi</meneame:user>
		<meneame:votes>1</meneame:votes>
		<meneame:karma>30</meneame:karma>
		<meneame:url>https://www.meneame.net/story/clickjacking-un-secreto-voces</meneame:url>
		<title>#7 Clickjacking: ¿un secreto a voces?</title>
		<link>https://www.meneame.net/story/clickjacking-un-secreto-voces/c07#c-7</link>
		<pubDate>Fri, 26 Sep 2008 22:20:34 +0000</pubDate>
		<dc:creator>selvatgi</dc:creator>
		<guid>https://www.meneame.net/story/clickjacking-un-secreto-voces/c07#c-7</guid>
		<description><![CDATA[<p><em>&#34;que afecta a todos los navegadores (menos a lynx y similares)&#34;</em> Ya me lo parecia a mi... <a href="http://meneame.net/story/repente-tu-explorador-vuelve-loco-pone-hacer-clicks-solito-hipervincul/1#comment-6" title="meneame.net/story/repente-tu-explorador-vuelve-loco-pone-hacer-clicks-solito-hipervincul/1#comment-6" rel="nofollow">meneame.net/story/repente-tu-explorador-vuelve-loco-pone-hacer-clicks-</a></p><p>&#187;&nbsp;autor: <strong>selvatgi</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>2767465</meneame:comment_id>
		<meneame:link_id>484684</meneame:link_id>
		<meneame:order>6</meneame:order>
		<meneame:user>LoLoPoWeR</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>6</meneame:karma>
		<meneame:url>https://www.meneame.net/story/clickjacking-un-secreto-voces</meneame:url>
		<title>#6 Clickjacking: ¿un secreto a voces?</title>
		<link>https://www.meneame.net/story/clickjacking-un-secreto-voces/c06#c-6</link>
		<pubDate>Fri, 26 Sep 2008 22:12:50 +0000</pubDate>
		<dc:creator>LoLoPoWeR</dc:creator>
		<guid>https://www.meneame.net/story/clickjacking-un-secreto-voces/c06#c-6</guid>
		<description><![CDATA[<p><a class="tooltip c:484684-1" href="https://www.meneame.net/story/clickjacking-un-secreto-voces/c01#c-1" rel="nofollow">#1</a> +1, me quedao con cara de.. WTF! (¬¬)<br />
<br />
salu2!</p><p>&#187;&nbsp;autor: <strong>LoLoPoWeR</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>2767445</meneame:comment_id>
		<meneame:link_id>484684</meneame:link_id>
		<meneame:order>5</meneame:order>
		<meneame:user>rondamon</meneame:user>
		<meneame:votes>2</meneame:votes>
		<meneame:karma>24</meneame:karma>
		<meneame:url>https://www.meneame.net/story/clickjacking-un-secreto-voces</meneame:url>
		<title>#5 Clickjacking: ¿un secreto a voces?</title>
		<link>https://www.meneame.net/story/clickjacking-un-secreto-voces/c05#c-5</link>
		<pubDate>Fri, 26 Sep 2008 22:10:21 +0000</pubDate>
		<dc:creator>rondamon</dc:creator>
		<guid>https://www.meneame.net/story/clickjacking-un-secreto-voces/c05#c-5</guid>
		<description><![CDATA[<p>El sueño para los buscadores del karma en meneame.</p><p>&#187;&nbsp;autor: <strong>rondamon</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>2767324</meneame:comment_id>
		<meneame:link_id>484684</meneame:link_id>
		<meneame:order>4</meneame:order>
		<meneame:user>Tensk</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>11</meneame:karma>
		<meneame:url>https://www.meneame.net/story/clickjacking-un-secreto-voces</meneame:url>
		<title>#4 Clickjacking: ¿un secreto a voces?</title>
		<link>https://www.meneame.net/story/clickjacking-un-secreto-voces/c04#c-4</link>
		<pubDate>Fri, 26 Sep 2008 21:44:21 +0000</pubDate>
		<dc:creator>Tensk</dc:creator>
		<guid>https://www.meneame.net/story/clickjacking-un-secreto-voces/c04#c-4</guid>
		<description><![CDATA[<p><a class="tooltip c:484684-1" href="https://www.meneame.net/story/clickjacking-un-secreto-voces/c01#c-1" rel="nofollow">#1</a> a eso se le llama un &#34;click&#34;-hanger <img data-src="https://cdn.mnmstatic.net/v_149/img/menemojis/36/lol.gif" alt="xD" title=":lol: xD" width="18" height="18" src="https://cdn.mnmstatic.net/v_149/img/g.gif" class="emoji lazy" /></p><p>&#187;&nbsp;autor: <strong>Tensk</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>2767206</meneame:comment_id>
		<meneame:link_id>484684</meneame:link_id>
		<meneame:order>3</meneame:order>
		<meneame:user>--26018--</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>9</meneame:karma>
		<meneame:url>https://www.meneame.net/story/clickjacking-un-secreto-voces</meneame:url>
		<title>#3 Clickjacking: ¿un secreto a voces?</title>
		<link>https://www.meneame.net/story/clickjacking-un-secreto-voces/c03#c-3</link>
		<pubDate>Fri, 26 Sep 2008 21:18:38 +0000</pubDate>
		<dc:creator>--26018--</dc:creator>
		<guid>https://www.meneame.net/story/clickjacking-un-secreto-voces/c03#c-3</guid>
		<description><![CDATA[<p>[Usuario deshabilitado]</p><p>&#187;&nbsp;autor: <strong>--26018--</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>2767184</meneame:comment_id>
		<meneame:link_id>484684</meneame:link_id>
		<meneame:order>2</meneame:order>
		<meneame:user>--96678--</meneame:user>
		<meneame:votes>1</meneame:votes>
		<meneame:karma>22</meneame:karma>
		<meneame:url>https://www.meneame.net/story/clickjacking-un-secreto-voces</meneame:url>
		<title>#2 Clickjacking: ¿un secreto a voces?</title>
		<link>https://www.meneame.net/story/clickjacking-un-secreto-voces/c02#c-2</link>
		<pubDate>Fri, 26 Sep 2008 21:14:09 +0000</pubDate>
		<dc:creator>--96678--</dc:creator>
		<guid>https://www.meneame.net/story/clickjacking-un-secreto-voces/c02#c-2</guid>
		<description><![CDATA[<p>[Usuario deshabilitado]</p><p>&#187;&nbsp;autor: <strong>--96678--</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>2767167</meneame:comment_id>
		<meneame:link_id>484684</meneame:link_id>
		<meneame:order>1</meneame:order>
		<meneame:user>--26018--</meneame:user>
		<meneame:votes>4</meneame:votes>
		<meneame:karma>45</meneame:karma>
		<meneame:url>https://www.meneame.net/story/clickjacking-un-secreto-voces</meneame:url>
		<title>#1 Clickjacking: ¿un secreto a voces?</title>
		<link>https://www.meneame.net/story/clickjacking-un-secreto-voces/c01#c-1</link>
		<pubDate>Fri, 26 Sep 2008 21:10:42 +0000</pubDate>
		<dc:creator>--26018--</dc:creator>
		<guid>https://www.meneame.net/story/clickjacking-un-secreto-voces/c01#c-1</guid>
		<description><![CDATA[<p>[Usuario deshabilitado]</p><p>&#187;&nbsp;autor: <strong>--26018--</strong></p>]]></description>
	</item>

</channel>
</rss>
