<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CrazyDavinci&#039;s Blog &#124; Social Networking, Programming, Security, Web Development &#187; Vulnerability</title>
	<atom:link href="http://crazydavinci.net/vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://crazydavinci.net</link>
	<description>The Da Vinci Code - Social Networking - Friendster - Facebook - Networking - Security - Programming</description>
	<lastBuildDate>Fri, 20 Jan 2012 09:49:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Facebook XSS via iPhone, Android, Exporter for iPhoto and Toolbar for Firefox</title>
		<link>http://crazydavinci.net/2011/05/facebook-xss-via-iphone-android-exporter-for-iphoto-toolbar-for-firefox/</link>
		<comments>http://crazydavinci.net/2011/05/facebook-xss-via-iphone-android-exporter-for-iphoto-toolbar-for-firefox/#comments</comments>
		<pubDate>Wed, 04 May 2011 13:31:15 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
				<category><![CDATA[Facebook Tips]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=1522</guid>
		<description><![CDATA[Here we will discuss about Facebook XSS again, the last XSS method using iPhone prompt_feed.php has been filtered, they have patched the system, but not all the hole, they still left us chance to put another XSS onClick using the same app. You can still insert the XSS via iPhone app, via Android, via BlackBerry, [...]]]></description>
		<wfw:commentRss>http://crazydavinci.net/2011/05/facebook-xss-via-iphone-android-exporter-for-iphoto-toolbar-for-firefox/feed/</wfw:commentRss>
		<slash:comments>52</slash:comments>
<enclosure url="http://crazydavinci.info/music/TrailofTears-SignofTheSameless.mp3" length="1988569" type="audio/mpeg" />
		</item>
		<item>
		<title>Autopost Spamming using Facebook Mobile XSS</title>
		<link>http://crazydavinci.net/2011/03/autopost-spamming-using-facebook-mobile-xss/</link>
		<comments>http://crazydavinci.net/2011/03/autopost-spamming-using-facebook-mobile-xss/#comments</comments>
		<pubDate>Mon, 28 Mar 2011 04:46:29 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
				<category><![CDATA[Facebook Tips]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=1307</guid>
		<description><![CDATA[What has happened out there really pushes me to share this out. I call this an Autopost Spamming using Facebook Mobile XSS. I dont care anymore if this one will be filtered, the faster they fix it, the better. People dont seem to care how hard i tried to hide this code from facebook team. [...]]]></description>
		<wfw:commentRss>http://crazydavinci.net/2011/03/autopost-spamming-using-facebook-mobile-xss/feed/</wfw:commentRss>
		<slash:comments>31</slash:comments>
		</item>
		<item>
		<title>Facebook XSS onClick via iPhone</title>
		<link>http://crazydavinci.net/2011/03/facebook-xss-onclick-via-iphone/</link>
		<comments>http://crazydavinci.net/2011/03/facebook-xss-onclick-via-iphone/#comments</comments>
		<pubDate>Sat, 26 Mar 2011 23:42:20 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
				<category><![CDATA[Facebook Tips]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Facebook Apps]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=1283</guid>
		<description><![CDATA[Facebook XSS again. This time is activated onClick via Facebook iPhone application. I decided to reveal this to public, as one of our friends has found this accidentally and many have also posted it publicly on their wall. sooner or later they will find out then patch this vulnerability again anyway. This XSS vulnerability was [...]]]></description>
		<wfw:commentRss>http://crazydavinci.net/2011/03/facebook-xss-onclick-via-iphone/feed/</wfw:commentRss>
		<slash:comments>32</slash:comments>
<enclosure url="http://crazydavinci.info/music/TrailofTears-SignofTheSameless.mp3" length="1988569" type="audio/mpeg" />
		</item>
		<item>
		<title>Google Site Hacked in Early 2011</title>
		<link>http://crazydavinci.net/2011/01/google-site-hacked-early-2011/</link>
		<comments>http://crazydavinci.net/2011/01/google-site-hacked-early-2011/#comments</comments>
		<pubDate>Sat, 08 Jan 2011 15:00:20 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=1159</guid>
		<description><![CDATA[It seem’s Google Bangladesh suffered from a DNS Hijack today, January 8, 2011, showing a weird hipster page playing a hiphop song, claiming that Google Bangladesh got “OwN3D by TiGER-M@TE. Visitors of the company’s Bangladesh search site (Google.com.bd) see a defaced landing page rather than the usual search site. It was a DNS Hijack, Mr. [...]]]></description>
		<wfw:commentRss>http://crazydavinci.net/2011/01/google-site-hacked-early-2011/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Google Vulnerability Reward Program</title>
		<link>http://crazydavinci.net/2010/11/google-vulnerability-reward-program/</link>
		<comments>http://crazydavinci.net/2010/11/google-vulnerability-reward-program/#comments</comments>
		<pubDate>Tue, 02 Nov 2010 18:19:26 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=1144</guid>
		<description><![CDATA[Google offers money rewards for finding vulnerabilities in their web application stuffs. Google will now pay you to find and report vulnerabilities in its various Web properties. The company made the announcement yesterday, and it applies to sites like google.com, youtube.com, and orkut.com. Should you report a qualifying bug, you can expect to walk away with hard cash range from $500 to $3,133.70.]]></description>
		<wfw:commentRss>http://crazydavinci.net/2010/11/google-vulnerability-reward-program/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Friendster XSS Through FBML</title>
		<link>http://crazydavinci.net/2010/08/friendster-xss-through-fbml/</link>
		<comments>http://crazydavinci.net/2010/08/friendster-xss-through-fbml/#comments</comments>
		<pubDate>Sun, 15 Aug 2010 11:41:43 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
				<category><![CDATA[Linker]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=1039</guid>
		<description><![CDATA[Status : Filtered (September, 2010) Released : August, 2010 Author : no_one Greetings : Angell de Ville &#038; The Friendster Team MyFeeling Widget Linker The last shoutout linker has been filtered already about a month after being released. Now i&#8217;m trying to share again another persistent xss on friendster that can be used to add [...]]]></description>
		<wfw:commentRss>http://crazydavinci.net/2010/08/friendster-xss-through-fbml/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>XSS on Twitter</title>
		<link>http://crazydavinci.net/2010/07/xss-on-twitter/</link>
		<comments>http://crazydavinci.net/2010/07/xss-on-twitter/#comments</comments>
		<pubDate>Sun, 18 Jul 2010 13:54:43 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
				<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=988</guid>
		<description><![CDATA[Twitter Persistent XSS - Searching for XSS hole on social networking websites is really fun indeed. It feels like you have your own satisfaction whenever you find it by yourself. the XSS vulnerability on Tagged, Multiply, Friendster or even Facebook have been posted here before]]></description>
		<wfw:commentRss>http://crazydavinci.net/2010/07/xss-on-twitter/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>XSS On Friendster</title>
		<link>http://crazydavinci.net/2010/05/xss-on-friendster/</link>
		<comments>http://crazydavinci.net/2010/05/xss-on-friendster/#comments</comments>
		<pubDate>Sat, 15 May 2010 23:09:51 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
				<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Friendster Tweaking]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/2010/05/xss-on-friendster/</guid>
		<description><![CDATA[Recently, many friendster users leave and move to facebook. That&#8217;s probably because facebook provides more easyness and interactivity than friendster, many cool games, chat, usefull applications, etc. Friendster seems to follow facebook too now, they tried to add anything facebook has on their page. They even tried to provide us chat facility like the one [...]]]></description>
		<wfw:commentRss>http://crazydavinci.net/2010/05/xss-on-friendster/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>XSS On Multiply</title>
		<link>http://crazydavinci.net/2010/03/xss-on-multiply/</link>
		<comments>http://crazydavinci.net/2010/03/xss-on-multiply/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 02:19:11 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
				<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=823</guid>
		<description><![CDATA[Status : Active Multiply is a social networking service with an emphasis on allowing users to share media &#8211; such as photos, videos and blog entries &#8211; with their &#8220;real-world&#8221; network. The website was launched in March 2004 and is privately held with backing by VantagePoint Venture Partners, Point Judith Capital, Transcosmos, and private investors. [...]]]></description>
		<wfw:commentRss>http://crazydavinci.net/2010/03/xss-on-multiply/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>XSS on Tagged</title>
		<link>http://crazydavinci.net/2010/03/xss-on-tagged/</link>
		<comments>http://crazydavinci.net/2010/03/xss-on-tagged/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 00:54:31 +0000</pubDate>
		<dc:creator>Joy</dc:creator>
				<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://crazydavinci.net/?p=818</guid>
		<description><![CDATA[Status : Active Tagged is the 3rd largest social network in the US, and has over 80 million members worldwide. Lately i have also found a hole to insert XSS vector on their profile page. You can see it live on this page Screenshot: What&#8217;s Next? Incoming search terms:tagged]]></description>
		<wfw:commentRss>http://crazydavinci.net/2010/03/xss-on-tagged/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

