Christian Heilmann

Don’t click this – a clickjacking experiment currently hammering twitter

Thursday, February 12th, 2009 at 7:29 pm

Reverse psychology is an interesting thing. Currently Twitter is being hammered by thousands of people twittering about a page that has a button that tells them not to click it. Why do they do it? Because they are told not to. How come they are twittering about it? A small thing called clickjacking.

Scott Schiller shows in a screenshot how the trick works:

The page with the don’t click button actually has an iframe over the button that loads your twitter.com/home page with the predefined tweet about going to the site. The iframe also positions your update button to cover the “don’t click this” button and has an opacity of 0 so you do submit your tweet without knowing it.

The scam works. If you currently check twitter search for “don’t click” then you’ll have an amazing amount of fresh tweets every few seconds. There’s also a French version in the wild

So if you get the tweet, don’t follow the page. If you see a button to click, be very wary of what is going on there!

Tags: , , ,

Share on Mastodon (needs instance)

Share on BlueSky

Newsletter

Check out the Dev Digest Newsletter I write every week for WeAreDevelopers. Latest issues:

Don't stop thinking, AI Slop vs. OSS Security, rolling your own S3 Despite AI you still need to think, Bitter lessons from building AI products,  AI Slop vs. OSS security and pointer pointer…
200: Building for the web, what's left after rm -rf & 🌊🐴 vs AI What remains after you do a rm -rf? Why do LLMs know about a seahorse emoji? What image formats should you use? How private is your car?
Word is Doomed, Flawed LLM benchmarks, hard sorting and CSS mistakes Spot LLM benchmark flaws, learn why sorting is hard, how to run Doom in Word and how to say "no" like a manager.
30 years of JS, Browser AI, how attackers use GenAI, whistling code Learn how to use AI in your browser and not on the cloud, why AI makes different mistakes than humans and go and whistle up some code!
197: Dunning-Kruger steroids, state of cloud security, puppies>beer

My other work: