[Noisebridge-discuss] Rubin is hawt.

Micah Lee micahflee at gmail.com
Tue Nov 3 02:23:52 UTC 2009


>
> One technique could be to write another JS script that identifies the
> radio button that is next to the text "Rubin", mark it as selected,
> then fire the click handler for the submit button. The guy behind
> del.icio.us did a similar attack on a poll site using del.icio.us at
> one point, essentially sending all his visitors as unaware ballot
> stuffers, each with their own unique IP.
>


But you'd need to find a cross site scripting vulnerability somewhere on
that page to make this code run for everyone who goes there, right? Also,
everyone who goes there wouldn't be able to vote, because they already voted
for Rubin. Hawt.

Micah
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.noisebridge.net/pipermail/noisebridge-discuss/attachments/20091102/895bce36/attachment-0003.html>


More information about the Noisebridge-discuss mailing list