XSS on Twitter

Posted by: Joy  :  Category: Vulnerability

Twitter XSS Searching for XSS hole on social networking websites is really fun indeed. It feels like you have your own satisfaction whenever you find it by yourself. the XSS vulnerability on Tagged, Multiply, Friendster or even Facebook have been posted here before and some has not been patched.. lolz..

About a month a go, when i was too busy with my daily activites on the real life, i didnt realize that one of our mods on Forum Balikita named H4×0r-x0x found one again on twitter, i’m amazed, good job dude. If i’m not mistaken the vulnerability left on twitter oauth application module, especially on application name

Read more…

Facebook Visitor Info

Posted by: Joy  :  Category: Facebook Tips

Facebook Visitor Log Here i go again, right now i’m gonna write a brief review to the social network application i made on last may 2010. As it shows users their own private information such as basic info, birthday, address, mobile number, ip address, email and website, etc, i call it Facebook Visitor Info.

Screenshot :
Read more…

Add Profile Box Using Facebook Application

Posted by: Joy  :  Category: Facebook Tips, Programming

Facebook LogoMost of my friends who are eager on developing facebook application ask me about how to create add profile box to their profile. Here, i’m gonna show you how to make it. Lets assume that you already understand the basic steps to create facebook application using php platform.

Profile.setFBML – That’s what we’re gonna use to add the profile box, you can read more about it on Facebook Developer Wiki

Read more…

XSS On Friendster

Posted by: Joy  :  Category: Vulnerability

Friendster XSSRecently, many friendster users leave and move to facebook. That’s probably because facebook provides more easyness and interactivity than friendster, many cool games, chat, usefull applications, etc. Friendster seems to follow facebook too now, they tried to add anything facebook has on their page. They even tried to provide us chat facility like the one on facebook, but it has not been implemented yet untill now. There are some more things that friendster try to follow, you can see how their activity stream, also link sharer, etc.

OK, let’s go staright to the topic, i accidentally found another XSS vulnerability “again” on their file, named sharer.php. It doesnt sanitize parameter correctly.

Read more…