November 02, 2010
Posted by: Joy : Category:
Security,
Vulnerability

Back in January of this year, the Chromium open source project
launched a well-received vulnerability reward program. In the months since launch, researchers reporting a wide range of great bugs have received rewards — a small summary of which can be found in the
Hall of Fame. They’ve seen a sustained increase in the number of high quality reports from researchers, and their combined efforts are contributing to a more secure Chromium browser for millions of users.
Today, They are announcing an experimental new vulnerability reward program that applies to Google web properties. They already enjoy working with an array of researchers to improve Google security, and some individuals who have provided high caliber reports are listed on Their credits page. As well as enabling them to thank regular contributors in a new way, they hope their new program will attract new researchers and the types of reports that help make their users safer.
Read more…
August 15, 2010
Posted by: Joy : Category:
Linker,
Vulnerability

Status : Filtered (September, 2010)
Released : August, 2010
Author : no_one
Greetings : Angell de Ville & The Friendster Team
MyFeeling Widget Linker
The last shoutout linker has been filtered already about a month after being released. Now i’m trying to share again another persistent xss on friendster that can be used to add layouts to our profile. Here, we’re gonna use the old FBML platform on friendster applications. as you might already know, actually this platform was already removed from their developer page about a year ago, but some of the old ones are still intact.
OK, let’s just go straight to the steps. Follow these instructions carefully :
Read more…
July 18, 2010
Posted by: Joy : Category:
Vulnerability

Searching for XSS hole on social networking websites is really fun indeed. It feels like you have your own satisfaction whenever you find it by yourself. the XSS vulnerability on Tagged, Multiply, Friendster or even Facebook have been posted here before and some has not been patched.. lolz..
About a month a go, when i was too busy with my daily activites on the real life, i didnt realize that one of our mods on Forum Balikita named H4x0r-x0x found one again on twitter, i’m amazed, good job dude. If i’m not mistaken the vulnerability left on twitter oauth application module, especially on application name
Read more…
May 15, 2010
Posted by: Joy : Category:
Vulnerability

Recently, many friendster users leave and move to facebook. That’s probably because facebook provides more easyness and interactivity than friendster, many cool games, chat, usefull applications, etc. Friendster seems to follow facebook too now, they tried to add anything facebook has on their page. They even tried to provide us chat facility like the one on facebook, but it has not been implemented yet untill now. There are some more things that friendster try to follow, you can see how their activity stream, also link sharer, etc.
OK, let’s go staright to the topic, i accidentally found another XSS vulnerability “again” on their file, named sharer.php. It doesnt sanitize parameter correctly.
Read more…