<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:wfw="http://wellformedweb.org/CommentAPI/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom"
    xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    >

<channel>
    <title>Webmonkey &#187; bug</title>
    <atom:link href="http://www.webmonkey.com/tag/bug/feed/" rel="self" type="application/rss+xml" />
    <link>http://www.webmonkey.com</link>
    <description>The Web Developer&#039;s Resource</description>
    <lastBuildDate>Fri, 05 Apr 2013 20:20:46 +0000</lastBuildDate>
    <language>en-US</language>
    <sy:updatePeriod>hourly</sy:updatePeriod>
    <sy:updateFrequency>1</sy:updateFrequency>
    <generator>http://wordpress.org/?v=3.4.2</generator>
    
    <item>
        <title>Beware of iPhone Clickjacking: Update to 2.2</title>
        <link>http://www.webmonkey.com/2008/11/beware_of_iphone_clickjacking_update_to_2dot2/</link>
        <comments>http://www.webmonkey.com/2008/11/beware_of_iphone_clickjacking_update_to_2dot2/#comments</comments>
        <pubDate>Mon, 24 Nov 2008 19:15:25 +0000</pubDate>

                <dc:creator>Adam Duvander</dc:creator>

        <guid isPermaLink="false">http://www.webmonkey.com/blog/bewareofiphoneclickjackingupdateto22</guid>
        		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[clickjacking]]></category>
		<category><![CDATA[CSS]]></category>
		<category><![CDATA[iPhone]]></category>
        <description><![CDATA[An iPhone clickjacking attack was fixed with last week&#8217;s release of the 2.2 software. Prior versions contained a CSS transforms bug that caused iframe content to appear as part of the actual page. It looks like the bug never saw malicious use in the wild, because the developers who noticed it alerted Apple and kept [...]]]></description>

            <content:encoded><![CDATA[<p><!-- wpautop enabled --><img class="blogimg" src="http://howto.wired.com/mediawiki/images/Iphone-clickjacking.png" alt="Example password jacking on iPhone" />An <a href="http://ejohn.org/blog/clickjacking-iphone-attack/">iPhone clickjacking attack</a> was fixed with last week&#8217;s release of the 2.2 software. Prior versions contained a <a href="http://webkit.org/blog/130/css-transforms/">CSS transforms</a> bug that caused iframe content to appear as part of the actual page.</p>
<p>It looks like the bug never saw malicious use in the wild, because the developers who noticed it alerted Apple and kept the bug secret while it was fixed. Like other <a href="http://www.webmonkey.com/blog/A_Look_at_the__Clickjacking__Web_Attack_and_Why_You_Should_Worry">clickjacking attacks</a>, the most likely use is to get a user to inadvertently click an ad. Although, an even more dangerous example is shown to harvest passwords.</p>
<p>If the <a href="http://blog.wired.com/gadgets/2008/11/apple-releases.html">StreetView and Maps additions</a> in the latest iPhone software wasn&#8217;t enough to get you to download the free update, let this attack be reason enough.</p>
<p>Though the bug was apparently discovered by developer <a href="http://waynepan.com/">Wayne Pan</a>, it was submitted by jQuery creator John Resig. Resig just keeps showing up for his various work. In addition to jQuery, he&#8217;s <a href="http://www.webmonkey.com/blog/Resig_Brings_Structure_to_Firebug">on the Firebug team at Mozilla</a>, <a href="http://www.webmonkey.com/blog/Chrome_is_Fast__But_Not_That_Fast">performance testing browsers</a> and <a href="http://www.webmonkey.com/blog/New_JavaScript_Library_Creates_Amazing_Animations">creating JavaScript animations</a>.</p>
<p><strong>See also:</strong></p>
<ul>
<li><a href="http://www.webmonkey.com/blog/A_Look_at_the__Clickjacking__Web_Attack_and_Why_You_Should_Worry">A Look at the &#8216;Clickjacking&#8217; Web Attack and Why You Should Worry</a></li>
<li><a href="http://www.webmonkey.com/blog/Hackers_are_Watching_You:_Flash_Clickjacking_Vulnerability_Exposes_Webcams_and_Mics">Hackers Are Watching You: Flash Clickjacking Vulnerability Exposes Webcams and Mics</a></li>
<li><a href="http://www.webmonkey.com/blog/Flash_Player_10_Solves_Some__but_not_all__Clickjacking__Attacks">Flash Player 10 Solves Some, but not all &#8216;Clickjacking&#8217; Attacks</a></li>
</ul>
<div id='linker_widget' class='contextly-widget'></div>]]></content:encoded>
            <wfw:commentRss>http://www.webmonkey.com/2008/11/beware_of_iphone_clickjacking_update_to_2dot2/feed/</wfw:commentRss>
        <slash:comments>0</slash:comments>

        
    </item>
    </channel>
</rss>