Nasty Facebook picture attack based on “self-XSS” – how does this work?
Facebook has confirmed that a series of pornographic and violent images posted on user walls this week were the result of a self-xss attack. XSS = cross site scripting. Self-XSS means that the malicious script was actually activated by a user and was not part of some hidden webpage code.