<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Evil Blogging &#187; css</title>
	<atom:link href="http://buckrobinson.com/tag/css/feed/" rel="self" type="application/rss+xml" />
	<link>http://buckrobinson.com</link>
	<description>Technology with an attitude</description>
	<lastBuildDate>Fri, 23 Jul 2010 12:59:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Css hacks</title>
		<link>http://buckrobinson.com/rants/css-hacks/</link>
		<comments>http://buckrobinson.com/rants/css-hacks/#comments</comments>
		<pubDate>Sat, 18 Jul 2009 03:15:34 +0000</pubDate>
		<dc:creator>Evil Buck</dc:creator>
				<category><![CDATA[Rants]]></category>
		<category><![CDATA[attacks]]></category>
		<category><![CDATA[css]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[programming]]></category>

		<guid isPermaLink="false">http://buckrobinson.com/rants/css-hacks/</guid>
		<description><![CDATA[I was just reminded of some css attacks that I had used just toying around. I was reminded because an update came across my rss feeds &#8211; yammer updated it&#8217;s Adobe Air client. This started when we started using yammer for inter-office communications among the programmers. Of course we had one who always tested the [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>I was just reminded of some css attacks that I had used just toying around. I was reminded because an update came across my rss feeds &#8211; yammer updated it&#8217;s Adobe Air client.</p>
<p align="left">This started when we started using yammer for inter-office communications among the programmers. Of course we had one who always tested the bounds of security, not for anything illegal, but for an excercise. He instantly started to try and find holes with yammer. I can&#8217;t remember specifics, but I think he started with script injection attacks. He of course was met with opposition by yammer&#8217;s filtering.</p>
<p align="left">My interest was peaked. The first thing I did was try adding a script tag. That was filtered, good yammer. Then adding css to change the page layout and hide logos. Aha! Injecting a style tag worked. At least it worked through the Air client. Now what to do from here?</p>
<p align="left">How about injecting my own scripts from css content property? This obvious hack seemed to work. I made a publicly accessible script and and added a script tag to the yammer page via css content property. The script was simple, it just changed some of the text and animated some items around. It didn&#8217;t work on all browsers though. It was enough to get a response from some of the guys yelling, &#8220;Hey! What happenned to Yammer?&#8221;.</p>
<p align="left">It was an interesting experiment. The hack took about 5 minutes mostly that long because of finding a public spot to host the javascript from. The code for the hack was: <code>#some_unique_id:after { content: '&amp;lt;script src="myscript.js"&amp;gt;&amp;lt;/script&amp;gt;'}</code></p>
<p>This was on a Friday afternoon. I removed the posts from Yammer so they wouldn&#8217;t disturb the rest of our users anymore, or the global feed that is probably on a big screen somewhere in the Yammer offices.</p>
<p align="left">Come Monday, I login to my system, Yammer starts up and voila! It has an update for the Air client. And wouldn&#8217;t you know, the css hack is no longer viable. These guys were on top of it. Also another reason I think they have a global feed running in their office.</p>
<div class="bleezer-tags:css, hack, software">
<p style="font-size:10px;text-align:right;">Technorati: <a rel="tag" href="http://www.technorati.com/tag/css" onclick="urchinTracker('/outgoing/www.technorati.com/tag/css?referer=');">css</a> <a rel="tag" href="http://www.technorati.com/tag/hack" onclick="urchinTracker('/outgoing/www.technorati.com/tag/hack?referer=');">hack</a> <a rel="tag" href="http://www.technorati.com/tag/software" onclick="urchinTracker('/outgoing/www.technorati.com/tag/software?referer=');">software</a></p>
</div>
<div class="bleezer-powered">
<p style="font-size:10px;text-align:right;"><em>Powered by <a href="http://www.bleezer.com" onclick="urchinTracker('/outgoing/www.bleezer.com?referer=');">Bleezer</a></em></p>
</div>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fcss-hacks%2F&amp;title=Css+hacks" title="Slashdot It!" onclick="urchinTracker('/outgoing/slashdot.org/bookmark.pl?url=http_3A_2F_2Fbuckrobinson.com_2Frants_2Fcss-hacks_2F_amp_title=Css+hacks&amp;referer=');"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fcss-hacks%2F&amp;title=Css+hacks" title="Digg This Story" onclick="urchinTracker('/outgoing/digg.com/submit?phase=2_amp_url=http_3A_2F_2Fbuckrobinson.com_2Frants_2Fcss-hacks_2F_amp_title=Css+hacks&amp;referer=');"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fcss-hacks%2F&amp;title=Css+hacks" title="Reddit" onclick="urchinTracker('/outgoing/reddit.com/submit?url=http_3A_2F_2Fbuckrobinson.com_2Frants_2Fcss-hacks_2F_amp_title=Css+hacks&amp;referer=');"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fcss-hacks%2F&amp;title=Css+hacks" title="Save to del.icio.us" onclick="urchinTracker('/outgoing/del.icio.us/post?url=http_3A_2F_2Fbuckrobinson.com_2Frants_2Fcss-hacks_2F_amp_title=Css+hacks&amp;referer=');window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fcss-hacks%2F&amp;title=Css+hacks', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fcss-hacks%2F" title="Share on Facebook" onclick="urchinTracker('/outgoing/www.facebook.com/share.php?u=http_3A_2F_2Fbuckrobinson.com_2Frants_2Fcss-hacks_2F&amp;referer=');"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fcss-hacks%2F" title="Add to my Technorati Favorites" onclick="urchinTracker('/outgoing/technorati.com/faves?add=http_3A_2F_2Fbuckrobinson.com_2Frants_2Fcss-hacks_2F&amp;referer=');"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fcss-hacks%2F&amp;title=Css+hacks" title="Save to Google Bookmarks" onclick="urchinTracker('/outgoing/www.google.com/bookmarks/mark?op=edit_amp_output=popup_amp_bkmk=http_3A_2F_2Fbuckrobinson.com_2Frants_2Fcss-hacks_2F_amp_title=Css+hacks&amp;referer=');"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fcss-hacks%2F&amp;title=Css+hacks" title="Stumble it!" onclick="urchinTracker('/outgoing/www.stumbleupon.com/submit?url=http_3A_2F_2Fbuckrobinson.com_2Frants_2Fcss-hacks_2F_amp_title=Css+hacks&amp;referer=');"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://buckrobinson.com/rants/css-hacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Theme</title>
		<link>http://buckrobinson.com/rants/new-theme/</link>
		<comments>http://buckrobinson.com/rants/new-theme/#comments</comments>
		<pubDate>Mon, 19 Nov 2007 22:05:29 +0000</pubDate>
		<dc:creator>Evil Buck</dc:creator>
				<category><![CDATA[Rants]]></category>
		<category><![CDATA[css]]></category>
		<category><![CDATA[theme]]></category>

		<guid isPermaLink="false">http://blog.buckrobinson.com/?p=115</guid>
		<description><![CDATA[I installed a new theme after a couple of years of neglecting the site. I only changed the default cursor for links. For some retarded reason, Bob decided to use a crosshair. I thought I accidentally enabled screenshot selection until I realized his theme changed the css cursor styling to something that is totally non-intuitive. [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>I installed a new theme after a couple of years of neglecting the site. I only changed the default cursor for links. For some retarded reason, Bob decided to use a crosshair. I thought I accidentally enabled screenshot selection until I realized his theme changed the css cursor styling to something that is totally non-intuitive. Good job on the rest of the theme though. I probably won&#8217;t bastardize too much more of it.<span style="text-decoration: line-through" class="Apple-style-span"> Except for maybe this baby blue border around the container.</span></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fnew-theme%2F&amp;title=New+Theme" title="Slashdot It!" onclick="urchinTracker('/outgoing/slashdot.org/bookmark.pl?url=http_3A_2F_2Fbuckrobinson.com_2Frants_2Fnew-theme_2F_amp_title=New+Theme&amp;referer=');"><img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fnew-theme%2F&amp;title=New+Theme" title="Digg This Story" onclick="urchinTracker('/outgoing/digg.com/submit?phase=2_amp_url=http_3A_2F_2Fbuckrobinson.com_2Frants_2Fnew-theme_2F_amp_title=New+Theme&amp;referer=');"><img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fnew-theme%2F&amp;title=New+Theme" title="Reddit" onclick="urchinTracker('/outgoing/reddit.com/submit?url=http_3A_2F_2Fbuckrobinson.com_2Frants_2Fnew-theme_2F_amp_title=New+Theme&amp;referer=');"><img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fnew-theme%2F&amp;title=New+Theme" title="Save to del.icio.us" onclick="urchinTracker('/outgoing/del.icio.us/post?url=http_3A_2F_2Fbuckrobinson.com_2Frants_2Fnew-theme_2F_amp_title=New+Theme&amp;referer=');window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fnew-theme%2F&amp;title=New+Theme', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fnew-theme%2F" title="Share on Facebook" onclick="urchinTracker('/outgoing/www.facebook.com/share.php?u=http_3A_2F_2Fbuckrobinson.com_2Frants_2Fnew-theme_2F&amp;referer=');"><img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fnew-theme%2F" title="Add to my Technorati Favorites" onclick="urchinTracker('/outgoing/technorati.com/faves?add=http_3A_2F_2Fbuckrobinson.com_2Frants_2Fnew-theme_2F&amp;referer=');"><img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fnew-theme%2F&amp;title=New+Theme" title="Save to Google Bookmarks" onclick="urchinTracker('/outgoing/www.google.com/bookmarks/mark?op=edit_amp_output=popup_amp_bkmk=http_3A_2F_2Fbuckrobinson.com_2Frants_2Fnew-theme_2F_amp_title=New+Theme&amp;referer=');"><img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fbuckrobinson.com%2Frants%2Fnew-theme%2F&amp;title=New+Theme" title="Stumble it!" onclick="urchinTracker('/outgoing/www.stumbleupon.com/submit?url=http_3A_2F_2Fbuckrobinson.com_2Frants_2Fnew-theme_2F_amp_title=New+Theme&amp;referer=');"><img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /></a>
</span>]]></content:encoded>
			<wfw:commentRss>http://buckrobinson.com/rants/new-theme/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
