<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Frame Injection Fun</title>
	<atom:link href="http://www.gnucitizen.org/blog/frame-injection-fun/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/frame-injection-fun/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Mon, 12 Dec 2011 19:56:03 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
	<item>
		<title>By: JD</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-129668</link>
		<dc:creator>JD</dc:creator>
		<pubDate>Thu, 20 Jan 2011 14:52:44 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-129668</guid>
		<description>Filtering is not the best defense against XSS and HTMLi. Encoding output is. Filtering must prevent all possible combinations of mallicious input. Encoding encodes all output. Encoding is simpler and covers more of the threat domain naturally.</description>
		<content:encoded><![CDATA[<p>Filtering is not the best defense against XSS and HTMLi. Encoding output is. Filtering must prevent all possible combinations of mallicious input. Encoding encodes all output. Encoding is simpler and covers more of the threat domain naturally.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .:[ d4 n3wS ]:. &#187; Blog Archive &#187; Frame injection PoC: gmail phishing..</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-128752</link>
		<dc:creator>.:[ d4 n3wS ]:. &#187; Blog Archive &#187; Frame injection PoC: gmail phishing..</dc:creator>
		<pubDate>Wed, 25 Aug 2010 04:18:45 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-128752</guid>
		<description>[...] Origine de l&#8217;article : http://www.gnucitizen.org/blog/frame-injection-fun/ [...]</description>
		<content:encoded><![CDATA[<p>[...] Origine de l&#8217;article : <a href="http://www.gnucitizen.org/blog/frame-injection-fun/" rel="nofollow">http://www.gnucitizen.org/blog.....ction-fun/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: What&#8217;s new in web hacking techniques of 2008</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-128136</link>
		<dc:creator>What&#8217;s new in web hacking techniques of 2008</dc:creator>
		<pubDate>Tue, 09 Feb 2010 05:35:59 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-128136</guid>
		<description>[...] Frame Injection Fun [...]</description>
		<content:encoded><![CDATA[<p>[...] Frame Injection Fun [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GigA: Todo es seguro ~~: iFrame Injection &#171; El camello, el LeÃ³n y el niÃ±o. O la evoluciÃ³n del perro al lobo.</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-127597</link>
		<dc:creator>GigA: Todo es seguro ~~: iFrame Injection &#171; El camello, el LeÃ³n y el niÃ±o. O la evoluciÃ³n del perro al lobo.</dc:creator>
		<pubDate>Mon, 06 Jul 2009 07:35:30 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-127597</guid>
		<description>[...] Leer mÃ¡s.   Mi comentario: La evoluciÃ³n de los sistemas es anÃ¡logo al de las especies. Solo sobreviven los fuertes. Con lo que redunda en mejores sistemas. Las vÃ­ctimas solo son efectos colaterales de la evoluciÃ³n. Jo, menudo punto de vista, un tanto fascista creo que me ha salido. Lo voy a meditar [...]</description>
		<content:encoded><![CDATA[<p>[...] Leer mÃ¡s.   Mi comentario: La evoluciÃ³n de los sistemas es anÃ¡logo al de las especies. Solo sobreviven los fuertes. Con lo que redunda en mejores sistemas. Las vÃ­ctimas solo son efectos colaterales de la evoluciÃ³n. Jo, menudo punto de vista, un tanto fascista creo que me ha salido. Lo voy a meditar [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lightningã§Thunderbirdã«ToDoã‚„ã‚«ãƒ¬ãƒ³ãƒ€ãƒ¼ã‚’çµ±åˆã—ã‚ˆã† &#124; my96soft-é›†åˆçŸ¥ã®ã™ã°ã‚‰ã—ã•ã‚’æ±‚ã‚ã¦-</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-127001</link>
		<dc:creator>Lightningã§Thunderbirdã«ToDoã‚„ã‚«ãƒ¬ãƒ³ãƒ€ãƒ¼ã‚’çµ±åˆã—ã‚ˆã† &#124; my96soft-é›†åˆçŸ¥ã®ã™ã°ã‚‰ã—ã•ã‚’æ±‚ã‚ã¦-</dc:creator>
		<pubDate>Tue, 12 May 2009 09:44:05 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-127001</guid>
		<description>[...] å®Ÿéš›ã«Gmailã®ãƒ­ã‚°ã‚¤ãƒ³ç”»é¢ï¼ˆå½ï¼‰ä½œã‚ŠãŸã‹ã£ãŸã‚‰ã“ã¡ã‚‰ã®ã‚³ãƒ¼ãƒ‰ã‚’å‚è€ƒã«ä½œã£ã¦ã¿ã¦ã‚ˆã€‚ Frame Injection Fun &#124; GNUCITIZEN [...]</description>
		<content:encoded><![CDATA[<p>[...] å®Ÿéš›ã«Gmailã®ãƒ­ã‚°ã‚¤ãƒ³ç”»é¢ï¼ˆå½ï¼‰ä½œã‚ŠãŸã‹ã£ãŸã‚‰ã“ã¡ã‚‰ã®ã‚³ãƒ¼ãƒ‰ã‚’å‚è€ƒã«ä½œã£ã¦ã¿ã¦ã‚ˆã€‚ Frame Injection Fun | GNUCITIZEN [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: p3lo</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-126528</link>
		<dc:creator>p3lo</dc:creator>
		<pubDate>Wed, 15 Apr 2009 15:20:19 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-126528</guid>
		<description>I have worked to developp this technique, and i have constated that we can break the frame with:

&lt;pre&gt;&lt;code&gt;if (top.frames.length!=0) top.location=self.document.location;&lt;/code&gt;&lt;/pre&gt;

and

&lt;pre&gt;&lt;code&gt;document.location=&quot;http://evil.foo/login.php&quot;;&lt;/code&gt;&lt;/pre&gt;

The first script can be used to secure the page framed...</description>
		<content:encoded><![CDATA[<p>I have worked to developp this technique, and i have constated that we can break the frame with:</p>
<pre><code>if (top.frames.length!=0) top.location=self.document.location;</code></pre>
<p>and</p>
<pre><code>document.location="http://evil.foo/login.php";</code></pre>
<p>The first script can be used to secure the page framed&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Le migliori tecniche di Web Hacking del 2008 &#124; lonerunners.net</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-126312</link>
		<dc:creator>Le migliori tecniche di Web Hacking del 2008 &#124; lonerunners.net</dc:creator>
		<pubDate>Sun, 15 Mar 2009 17:19:08 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-126312</guid>
		<description>[...] Frame Injection Fun [...]</description>
		<content:encoded><![CDATA[<p>[...] Frame Injection Fun [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Heuristic Delta :: Top 70 Hacking Methods :: http://blogs.heuristicdelta.com</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-126130</link>
		<dc:creator>Heuristic Delta :: Top 70 Hacking Methods :: http://blogs.heuristicdelta.com</dc:creator>
		<pubDate>Wed, 25 Feb 2009 07:47:20 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-126130</guid>
		<description>[...] Frame Injection Fun [...]</description>
		<content:encoded><![CDATA[<p>[...] Frame Injection Fun [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Submit Your Top Web Hacking Techniques for 2008 &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-125697</link>
		<dc:creator>Submit Your Top Web Hacking Techniques for 2008 &#124; GNUCITIZEN</dc:creator>
		<pubDate>Fri, 30 Jan 2009 00:04:19 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-125697</guid>
		<description>[...] Frame Injection Fun [...]</description>
		<content:encoded><![CDATA[<p>[...] Frame Injection Fun [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GUYA.NET &#187; Blog Archive &#187; Google Hackathon was hacked</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-124264</link>
		<dc:creator>GUYA.NET &#187; Blog Archive &#187; Google Hackathon was hacked</dc:creator>
		<pubDate>Wed, 05 Nov 2008 00:45:13 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-124264</guid>
		<description>[...] I got was that I should report this somewhere in the GMail website. But, it&#8217;s already been reported, I [...]</description>
		<content:encoded><![CDATA[<p>[...] I got was that I should report this somewhere in the GMail website. But, it&#8217;s already been reported, I [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian 'pagvac' Pastor</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-124113</link>
		<dc:creator>Adrian 'pagvac' Pastor</dc:creator>
		<pubDate>Tue, 21 Oct 2008 07:07:13 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-124113</guid>
		<description>@Chintan: this is a problem of semantics, we could talk about it forever. It doesn&#039;t matter what you call it, the issue is still the same: you can insert third-party content while still showing mail.google.com in the address bar.

We did NOT come up with the term &quot;frame injection&quot; (just do a Google search), neither did we claim we came up with a new technique. The only reason why there has been some media interest is because Google is something everyone can relate to.

Thanks a lot for your feedback again btw.</description>
		<content:encoded><![CDATA[<p>@Chintan: this is a problem of semantics, we could talk about it forever. It doesn&#8217;t matter what you call it, the issue is still the same: you can insert third-party content while still showing mail.google.com in the address bar.</p>
<p>We did NOT come up with the term &#8220;frame injection&#8221; (just do a Google search), neither did we claim we came up with a new technique. The only reason why there has been some media interest is because Google is something everyone can relate to.</p>
<p>Thanks a lot for your feedback again btw.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chintan</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-124104</link>
		<dc:creator>Chintan</dc:creator>
		<pubDate>Sun, 19 Oct 2008 16:32:33 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-124104</guid>
		<description>@Adrian - I appreciate your explanation. But i still think an attacker is not adding any frame into victim&#039;s page. I think it can be termed as url redirection via frames. 

The reason the address bar reflects new url in a traditional url redirection attack is because the redirection is direct one (i.e. @page level). 

Since in this case the the functionality of the frame is to load an external url- which is abused to load an arbitrary page inside that frame, it will never show up in address bar (not even for the legitimate page). 

I repeat, an attacker is not injecting any frame into victim&#039;s webpage. Only the content of the existing frame changes as the domain is not restricted. Then how can one call it frame &quot;Injection&quot;?

I think the debate may be endless. Instead i give it up here. Feel free to call it anything you want. 

None the less, not a bad catch (just that it has been overhyped to reflect as a new kind of attack). I have always appreciated GNU Citizen for their innovations, but i cannot give credit for this one atleast.</description>
		<content:encoded><![CDATA[<p>@Adrian &#8211; I appreciate your explanation. But i still think an attacker is not adding any frame into victim&#8217;s page. I think it can be termed as url redirection via frames. </p>
<p>The reason the address bar reflects new url in a traditional url redirection attack is because the redirection is direct one (i.e. @page level). </p>
<p>Since in this case the the functionality of the frame is to load an external url- which is abused to load an arbitrary page inside that frame, it will never show up in address bar (not even for the legitimate page). </p>
<p>I repeat, an attacker is not injecting any frame into victim&#8217;s webpage. Only the content of the existing frame changes as the domain is not restricted. Then how can one call it frame &#8220;Injection&#8221;?</p>
<p>I think the debate may be endless. Instead i give it up here. Feel free to call it anything you want. </p>
<p>None the less, not a bad catch (just that it has been overhyped to reflect as a new kind of attack). I have always appreciated GNU Citizen for their innovations, but i cannot give credit for this one atleast.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Diversas vulnerabilidades en Google &#124; El blog de José Luís Zayas</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-124094</link>
		<dc:creator>Diversas vulnerabilidades en Google &#124; El blog de José Luís Zayas</dc:creator>
		<pubDate>Sat, 18 Oct 2008 14:33:50 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-124094</guid>
		<description>[...] La primera de ellas se trata de un Cross Domain Frame http://mail.google.com/imgres?imgurl=http://SecureGoogleMail&amp;imgrefurl=http%3a%2f%2fsnipurl.com/482f3 según podemos ver, un usuario que entrara en dicho link podría ser engañado y capturar sus credenciales de su cuenta Google, más información aquí. [...]</description>
		<content:encoded><![CDATA[<p>[...] La primera de ellas se trata de un Cross Domain Frame <a href="http://mail.google.com/imgres?imgurl=http://SecureGoogleMail&#038;imgrefurl=http%3a%2f%2fsnipurl.com/482f3" rel="nofollow">http://mail.google.com/imgres?......com/482f3</a> según podemos ver, un usuario que entrara en dicho link podría ser engañado y capturar sus credenciales de su cuenta Google, más información aquí. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frame injection exploits Google flaw &#124; Information Systems Security</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-124085</link>
		<dc:creator>Frame injection exploits Google flaw &#124; Information Systems Security</dc:creator>
		<pubDate>Fri, 17 Oct 2008 17:55:01 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-124085</guid>
		<description>[...] posted the frame-injection PoC example against Google on the GNUCitizen blog. He explained that frame injection works by inserting the URL of a third-party website into the [...]</description>
		<content:encoded><![CDATA[<p>[...] posted the frame-injection PoC example against Google on the GNUCitizen blog. He explained that frame injection works by inserting the URL of a third-party website into the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ethical Hackers &#187; Google Gmail, Other Apps, Vulnerable To Attack</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-124082</link>
		<dc:creator>Ethical Hackers &#187; Google Gmail, Other Apps, Vulnerable To Attack</dc:creator>
		<pubDate>Fri, 17 Oct 2008 03:13:59 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-124082</guid>
		<description>[...] ‘pagvac’ Pastor, a security researcher with GNUCitizen.org, on Friday posted proof-of-concept code that can inject a third-party page — a fake login page in Pastor’s example — while the [...]</description>
		<content:encoded><![CDATA[<p>[...] ‘pagvac’ Pastor, a security researcher with GNUCitizen.org, on Friday posted proof-of-concept code that can inject a third-party page — a fake login page in Pastor’s example — while the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian 'pagvac' Pastor</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-124066</link>
		<dc:creator>Adrian 'pagvac' Pastor</dc:creator>
		<pubDate>Thu, 16 Oct 2008 07:10:09 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-124066</guid>
		<description>@Chintan: sure it IS different. In a redirection attack, the URL in the browser&#039;s address bar changes to a non-trusted third-party site once the &quot;evil&quot; URL is visited. In a frame injection attack, the address bar remains showing the legitimate domain after the &quot;evil&quot; URL is visited.

It is called frame injection because the third-party content is inserted via a dynamically generated frame. Check the &#039;frame&#039; tags in the source code for more info.

@Daniel: I&#039;m actually against creating new vulnerability names, it just complicates things. The only reason I mentioned the term &quot;frame injection&quot; is because: 1) it&#039;s NOT a new term. 2) the filtering solution needed is different to the one required for &quot;pure&quot; XSS/HTMLi vulnerabilities as the attacker doesn&#039;t need to inject &quot;dangerous&quot; characters. At least generally speaking.</description>
		<content:encoded><![CDATA[<p>@Chintan: sure it IS different. In a redirection attack, the URL in the browser&#8217;s address bar changes to a non-trusted third-party site once the &#8220;evil&#8221; URL is visited. In a frame injection attack, the address bar remains showing the legitimate domain after the &#8220;evil&#8221; URL is visited.</p>
<p>It is called frame injection because the third-party content is inserted via a dynamically generated frame. Check the &#8216;frame&#8217; tags in the source code for more info.</p>
<p>@Daniel: I&#8217;m actually against creating new vulnerability names, it just complicates things. The only reason I mentioned the term &#8220;frame injection&#8221; is because: 1) it&#8217;s NOT a new term. 2) the filtering solution needed is different to the one required for &#8220;pure&#8221; XSS/HTMLi vulnerabilities as the attacker doesn&#8217;t need to inject &#8220;dangerous&#8221; characters. At least generally speaking.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Serviços do Google estão vulneráveis a Frame Injection &#124; Elvis Fernandes</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-124062</link>
		<dc:creator>Serviços do Google estão vulneráveis a Frame Injection &#124; Elvis Fernandes</dc:creator>
		<pubDate>Wed, 15 Oct 2008 11:40:05 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-124062</guid>
		<description>[...] O Adrian &#8216;pagvac&#8217; Pastor, da GNUCitizen, postou sua descoberta sobre a vulnerabilidade do google a ataques de Frame Injection. [...]</description>
		<content:encoded><![CDATA[<p>[...] O Adrian &#8216;pagvac&#8217; Pastor, da GNUCitizen, postou sua descoberta sobre a vulnerabilidade do google a ataques de Frame Injection. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim Manico</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-124058</link>
		<dc:creator>Jim Manico</dc:creator>
		<pubDate>Tue, 14 Oct 2008 18:00:26 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-124058</guid>
		<description>RE: Comments about about input validation above : you do NOT defend against XSS by input validation - thats one of the biggest misnomers in AppSec. You solve it via ENCODING data before presenting it to your users. ESAPI, for example, provides a variety of data encoding functions depending on context: encodeForHTML, encodeForHTMLEntity, encodeForJavascript, etc.</description>
		<content:encoded><![CDATA[<p>RE: Comments about about input validation above : you do NOT defend against XSS by input validation &#8211; thats one of the biggest misnomers in AppSec. You solve it via ENCODING data before presenting it to your users. ESAPI, for example, provides a variety of data encoding functions depending on context: encodeForHTML, encodeForHTMLEntity, encodeForJavascript, etc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Google Gmail, Other Apps, Vulnerable To Attackers , Hackers &#124; Tech At Hand Dot Net &#124; Philippines, Technology, SEO and Blogging</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-124053</link>
		<dc:creator>Google Gmail, Other Apps, Vulnerable To Attackers , Hackers &#124; Tech At Hand Dot Net &#124; Philippines, Technology, SEO and Blogging</dc:creator>
		<pubDate>Tue, 14 Oct 2008 09:03:48 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-124053</guid>
		<description>[...] Adrian &#8216;pagvac&#8217; Pastor, a security researcher with GNUCitizen.org, on Friday posted proof-of-concept code that can inject a third-party page &#8212; a fake login page in Pastor&#8217;s example &#8212; [...]</description>
		<content:encoded><![CDATA[<p>[...] Adrian &#8216;pagvac&#8217; Pastor, a security researcher with GNUCitizen.org, on Friday posted proof-of-concept code that can inject a third-party page &#8212; a fake login page in Pastor&#8217;s example &#8212; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chintan</title>
		<link>http://www.gnucitizen.org/blog/frame-injection-fun/comment-page-1/#comment-124049</link>
		<dc:creator>Chintan</dc:creator>
		<pubDate>Tue, 14 Oct 2008 02:16:29 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1568#comment-124049</guid>
		<description>Hi, I don&#039;t think its any thing different from URL Redirection (except that it is now wrapped with a new shiny marketing lingo). I still don&#039;t understand where the frame gets injected! It&#039;s just getting loaded from an external source.

Instead of loading Fake Gmail page, you can load any page instead. The following loads yahoo :P

http://mail.google.com/imgres?imgurl=http://yahoo.com&amp;imgrefurl=http://yahoo.com

Can some one please explain me the rationale for calling it a frame injection?</description>
		<content:encoded><![CDATA[<p>Hi, I don&#8217;t think its any thing different from URL Redirection (except that it is now wrapped with a new shiny marketing lingo). I still don&#8217;t understand where the frame gets injected! It&#8217;s just getting loaded from an external source.</p>
<p>Instead of loading Fake Gmail page, you can load any page instead. The following loads yahoo :P</p>
<p><a href="http://mail.google.com/imgres?imgurl=http://yahoo.com&#038;imgrefurl=http://yahoo.com" rel="nofollow">http://mail.google.com/imgres?...../yahoo.com</a></p>
<p>Can some one please explain me the rationale for calling it a frame injection?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

