Friendster XSS Through FBML

Posted by: Joy  :  Category: Linker, Vulnerability

Friendster FBML Hole Status : Active
Released : August, 2010
Author : no_one
Greetings : Angell de Ville & The Friendster Team

MyFeeling Widget Linker

The last shoutout linker has been filtered already about a month after being released. Now i’m trying to share again another persistent xss on friendster that can be used to add layouts to our profile. Here, we’re gonna use the old FBML platform on friendster applications. as you might already know, actually this platform was already removed from their developer page about a year ago, but some of the old ones are still intact.

OK, let’s just go straight to the steps. Follow these instructions carefully :
Read more…

Shoutout Friendster Linker 2010

Posted by: Joy  :  Category: Linker

Friendster Logo We know that most of friendster users are currently moving to facebook, one of the reason beside what facebook has probably because of the lack of updated friendster linker. My friend, Angell de Ville and i actually still have some working linker for private use when other forum offline because of this linker issue, but it wasn’t shared around yet on public as we’ve been busy on our real life, and we also got problem which makes us offline on forums. Now, i decided to publish this post and share one linker to be used just to see how friendster users respond to this linker, do they still have spirit to tweak their frienster profile or not like the way they used to be.
Read more…

XSS Widget Update

Posted by: Joy  :  Category: Linker

App Name : Classified
Status : Active
Platform : v1
Last Update : November 12, 2009
Credits : Switangell, The Cradle & Forum Balikita

We’re not sharing the widget here directly, you can get the info about it on our forums.

Kindly proceed here :
Read more…

Latest XSS Widget

Posted by: Joy  :  Category: Linker

Cute Pink Girl
Shared by: switpotato
Created: July 2009
Status : Filtered (August 2009)

Here’s another more friendster widget, that can serve as a vessel to inject your Cross-site Scripting (XSS) vector in your profile. Just follow the instructions carefully.

Read more…