<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>CrazyDavinci's Blog &#124; Friendster - Programming - Networking - Security</title>
	<atom:link href="http://crazydavinci.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://crazydavinci.net</link>
	<description>The Da Vinci Code - Friendster - Networking - Security - Programming</description>
	<pubDate>Tue, 09 Mar 2010 09:40:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>View Facebook Private Photos/Album</title>
		<link>http://crazydavinci.net/2010/03/view-facebook-private-photos-album/</link>
		<comments>http://crazydavinci.net/2010/03/view-facebook-private-photos-album/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 00:15:56 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
		
		<category><![CDATA[Miscellaneous Trick]]></category>

		<category><![CDATA[Facebook]]></category>

		<category><![CDATA[Hacking]]></category>

		<category><![CDATA[JavaScript]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=831</guid>
		<description><![CDATA[
The word private here means that facebook photos/album belong to those profile that are not listed on our friendslist but the privacy setting is set to everyone and the photos tab is hidden. Using this trick below we can reveal the album links. OK, lets try it using my profile as an example :
- Login [...]]]></description>
		<wfw:commentRss>http://crazydavinci.net/2010/03/view-facebook-private-photos-album/feed/</wfw:commentRss>
		</item>
		<item>
		<title>XSS On Multiply</title>
		<link>http://crazydavinci.net/2010/03/xss-on-multiply/</link>
		<comments>http://crazydavinci.net/2010/03/xss-on-multiply/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 02:19:11 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
		
		<category><![CDATA[Vulnerability]]></category>

		<category><![CDATA[Hacking]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=823</guid>
		<description><![CDATA[
Status : Active
Multiply is a social networking service with an emphasis on allowing users to share media - such as photos, videos and blog entries - with their &#8220;real-world&#8221; network. The website was launched in March 2004 and is privately held with backing by VantagePoint Venture Partners, Point Judith Capital, Transcosmos, and private investors. Multiply [...]]]></description>
		<wfw:commentRss>http://crazydavinci.net/2010/03/xss-on-multiply/feed/</wfw:commentRss>
		</item>
		<item>
		<title>XSS on Tagged</title>
		<link>http://crazydavinci.net/2010/03/xss-on-tagged/</link>
		<comments>http://crazydavinci.net/2010/03/xss-on-tagged/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 00:54:31 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
		
		<category><![CDATA[Vulnerability]]></category>

		<category><![CDATA[Hacking]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=818</guid>
		<description><![CDATA[
Status : Active
Tagged is the 3rd largest social network in the US, and has over 80 million members worldwide. Lately i have also found a hole to insert XSS vector on their profile page. You can see it live on this page
Screenshot:


What&#8217;s Next?  

]]></description>
		<wfw:commentRss>http://crazydavinci.net/2010/03/xss-on-tagged/feed/</wfw:commentRss>
		</item>
		<item>
		<title>XSS On Facebook</title>
		<link>http://crazydavinci.net/2010/02/xss-on-facebook/</link>
		<comments>http://crazydavinci.net/2010/02/xss-on-facebook/#comments</comments>
		<pubDate>Sun, 14 Feb 2010 00:36:02 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
		
		<category><![CDATA[Vulnerability]]></category>

		<category><![CDATA[Hacking]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=805</guid>
		<description><![CDATA[
Status : Active, Partially Patched (> March 2010)
As the slogan of this blog says there&#8217;s always a crack in everything, that&#8217;s how the light gets in, yes, it&#8217;s true, even on Facebook, there&#8217;re some holes left. The secret is left behind their application module. Around last November, 2009, holes for tweaking facebook found when i [...]]]></description>
		<wfw:commentRss>http://crazydavinci.net/2010/02/xss-on-facebook/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Facebook Apps - Lebay Wall Poster</title>
		<link>http://crazydavinci.net/2009/12/facebook-apps-wall-poster/</link>
		<comments>http://crazydavinci.net/2009/12/facebook-apps-wall-poster/#comments</comments>
		<pubDate>Wed, 23 Dec 2009 14:04:16 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
		
		<category><![CDATA[Programming]]></category>

		<category><![CDATA[Facebook]]></category>

		<category><![CDATA[PHP]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=772</guid>
		<description><![CDATA[

Lately, i&#8217;ve been playing with facebook application module and managed to create one simple facebook application called &#8220;Lebay Wall Poster&#8221;. I added bookmark, share and add to profile  button on canvas page, profile box available on profile page (wall tab) with animated picture when user click the button, you can see the preview on [...]]]></description>
		<wfw:commentRss>http://crazydavinci.net/2009/12/facebook-apps-wall-poster/feed/</wfw:commentRss>
		</item>
		<item>
		<title>XSS Widget Update</title>
		<link>http://crazydavinci.net/2009/09/xss-widget-update/</link>
		<comments>http://crazydavinci.net/2009/09/xss-widget-update/#comments</comments>
		<pubDate>Sat, 05 Sep 2009 20:55:40 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
		
		<category><![CDATA[Linker]]></category>

		<category><![CDATA[friendster]]></category>

		<category><![CDATA[Friendster Tweaking]]></category>

		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=759</guid>
		<description><![CDATA[

App Name : Classified
Status : Active
Platform : v1
Last Update : November 12, 2009
Credits : Switangell, The Cradle &#038; Forum Balikita
We&#8217;re not sharing the widget here directly, you can get the info about it on our forums.
Kindly proceed here :

- The Cradle
-  Forum Balikita
-  Switpotato
Historical Update :
- September 6, 2009 (fbOpen cloning/deleted)
- September 23, [...]]]></description>
		<wfw:commentRss>http://crazydavinci.net/2009/09/xss-widget-update/feed/</wfw:commentRss>
		</item>
		<item>
		<title>XSS On Indo TV Stations</title>
		<link>http://crazydavinci.net/2009/08/xss-on-indo-tv-stations/</link>
		<comments>http://crazydavinci.net/2009/08/xss-on-indo-tv-stations/#comments</comments>
		<pubDate>Fri, 28 Aug 2009 00:05:40 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
		
		<category><![CDATA[Vulnerability]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=745</guid>
		<description><![CDATA[
Here, we&#8217;re gonna show you XSS (Cross Site Scripting) and XFS (XSS From SQLi) bugs on some Indo TV Stations Websites.
As you might already know that Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications which allow code injection by malicious web users into the web pages viewed by [...]]]></description>
		<wfw:commentRss>http://crazydavinci.net/2009/08/xss-on-indo-tv-stations/feed/</wfw:commentRss>
		</item>
		<item>
		<title>View Page Source Trick &amp; Tool</title>
		<link>http://crazydavinci.net/2009/08/view-page-source-trick-tool/</link>
		<comments>http://crazydavinci.net/2009/08/view-page-source-trick-tool/#comments</comments>
		<pubDate>Mon, 10 Aug 2009 00:18:34 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
		
		<category><![CDATA[Web Development]]></category>

		<category><![CDATA[Tips & Trick]]></category>

		<category><![CDATA[Tools]]></category>

		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=731</guid>
		<description><![CDATA[
The view-source protocol is a URI scheme used in HTML to display the source code of a web page. Firefox and Internet Explorer both supported the view-source protocol, but support was dropped from Internet Explorer in Windows XP SP2 due to security problems. Firefox also suffered a similar security issue (by combining the view-source: and [...]]]></description>
		<wfw:commentRss>http://crazydavinci.net/2009/08/view-page-source-trick-tool/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Latest XSS Widget</title>
		<link>http://crazydavinci.net/2009/08/latest-xss-widget/</link>
		<comments>http://crazydavinci.net/2009/08/latest-xss-widget/#comments</comments>
		<pubDate>Tue, 04 Aug 2009 02:28:26 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
		
		<category><![CDATA[Linker]]></category>

		<category><![CDATA[friendster]]></category>

		<category><![CDATA[Friendster Tweaking]]></category>

		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=704</guid>
		<description><![CDATA[
Cute Pink Girl 
Shared by: switpotato 
Created: July 2009
Status : Filtered (August 2009) 
Here&#8217;s another more friendster widget, that can serve as a vessel to inject your Cross-site Scripting (XSS) vector in your profile. Just follow the instructions carefully.

Install the widget in your profile:
Click Here
You will be forced to log in to your Friendster account [...]]]></description>
		<wfw:commentRss>http://crazydavinci.net/2009/08/latest-xss-widget/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Friendster XSS Widget</title>
		<link>http://crazydavinci.net/2009/08/friendster-xss-widget/</link>
		<comments>http://crazydavinci.net/2009/08/friendster-xss-widget/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 17:00:17 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
		
		<category><![CDATA[Linker]]></category>

		<category><![CDATA[friendster]]></category>

		<category><![CDATA[Friendster Tweaking]]></category>

		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=695</guid>
		<description><![CDATA[
Status   : Classified
Author   : Classified
Created : Unknown 
Here’s another widget that can also serve as a vessel to inject your Cross-site Scripting (XSS) vector in your profile. Just follow the instructions carefully.
Protected content, please login or register to see the the rest of the content


JS Linker :  &#60;script src=&#34Your JS [...]]]></description>
		<wfw:commentRss>http://crazydavinci.net/2009/08/friendster-xss-widget/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
