XSS On Facebook

Posted by: Joy  :  Category: Vulnerability

Status : Active, Partially Patched (> March 2010)

As the slogan of this blog says there’s always a crack in everything, that’s how the light gets in, yes, it’s true, even on Facebook, there’re some holes left. The secret is left behind their application module. Around last November, 2009, holes for tweaking facebook found when i was looking for bugs, and the XSS was firstly only for IE + old Fx browser only.

Screenshot :

Read more…