Vcoderz Community
We create websites that have it all, beauty & brains
Lebanon Web Design & Development - Coddict
 

Go Back   Vcoderz Community > Computer Zone > Computers & Information Technologies

Notices

Computers & Information Technologies Ģ Everything related to computers and internet. ģ

Reply
 
Share Thread Tools Search this Thread
Old 09-03-2010   #1
Google

 
Google's Avatar
 
Last Online: 05-30-2013
Join Date: Jan 2008
Posts: 1,788
Thanks: 10,018
Thanked 1,100 Times in 651 Posts
Groans: 1
Groaned at 6 Times in 6 Posts
Default Facebook XSS in the wild

Check this, it was found today:
http://www.facebook.com/photo_search...29946463714673

Now hackers can benefit from this to hijack accounts until facebook fixes the bug.


__________________

Google is offline   Reply With Quote
Old 09-03-2010   #2
SysTaMatIcS
Registered Member
 
SysTaMatIcS's Avatar
 
Last Online: 10-14-2022
Join Date: Dec 2006
Posts: 10,467
Thanks: 14,136
Thanked 4,244 Times in 2,547 Posts
Groans: 186
Groaned at 198 Times in 120 Posts
Default

So i can write whatever i want in this? instead of heya , how can hacker make use of this?
<script>alert('HEYYAAA')</script>



__________________
problems of performance appraisal is that it sucks to memorize them
SysTaMatIcS is offline   Reply With Quote
Old 09-03-2010   #3
RUSSIAN
Registered Member
 
RUSSIAN's Avatar
 
Last Online: 10-08-2023
Join Date: Nov 2009
Posts: 569
Thanks: 838
Thanked 232 Times in 174 Posts
Groans: 24
Groaned at 16 Times in 13 Posts
Default

Replace it with any JS code you want.
__________________
What about a 500+ symbols long, colored signature with URL allowed and size limited to 7?
RUSSIAN is offline   Reply With Quote
Old 09-04-2010   #4
Google

 
Google's Avatar
 
Last Online: 05-30-2013
Join Date: Jan 2008
Posts: 1,788
Thanks: 10,018
Thanked 1,100 Times in 651 Posts
Groans: 1
Groaned at 6 Times in 6 Posts
Default

Quote:
Originally Posted by SysTaMatIcS View Post
So i can write whatever i want in this? instead of heya , how can hacker make use of this?
<script>alert('HEYYAAA')</script>



This HEYYAAA alert box is a proof of concept of the exploit. It means that you can inject JavaScript code on this page. Injecting JavaScript in the page means that you are able to steal other user's cookies. Stealing other user's cookie means you are able to impersonate that user and hijack his/her account.
__________________

Google is offline   Reply With Quote
The Following 4 Users Say Thank You to Google For This Useful Post:
Genius704 (09-04-2010), Justin (04-03-2011), RUSSIAN (09-04-2010), SysTaMatIcS (09-04-2010)
Old 09-06-2010   #5
Google

 
Google's Avatar
 
Last Online: 05-30-2013
Join Date: Jan 2008
Posts: 1,788
Thanks: 10,018
Thanked 1,100 Times in 651 Posts
Groans: 1
Groaned at 6 Times in 6 Posts
Default

This exploit is now fixed by Facebook team.
"Yalli darab darab, wyalli harab harab"
__________________

Google is offline   Reply With Quote
Old 04-02-2011   #6
Google

 
Google's Avatar
 
Last Online: 05-30-2013
Join Date: Jan 2008
Posts: 1,788
Thanks: 10,018
Thanked 1,100 Times in 651 Posts
Groans: 1
Groaned at 6 Times in 6 Posts
Default Another facebook xss found by me ;)

Video:

I reported this vulnerability to Facebook and xssed.com so it will soon be fixed. Enjoy for now
__________________

Google is offline   Reply With Quote
The Following 4 Users Say Thank You to Google For This Useful Post:
Abruzzy (04-03-2011), H@SSāN (04-03-2011), Justin (04-04-2011), Kingroudy (04-02-2011)
Old 04-03-2011   #7
SysTaMatIcS
Registered Member
 
SysTaMatIcS's Avatar
 
Last Online: 10-14-2022
Join Date: Dec 2006
Posts: 10,467
Thanks: 14,136
Thanked 4,244 Times in 2,547 Posts
Groans: 186
Groaned at 198 Times in 120 Posts
Default

lol get a job at fb , security counselor
__________________
problems of performance appraisal is that it sucks to memorize them
SysTaMatIcS is offline   Reply With Quote
Reply

  Vcoderz Community > Computer Zone > Computers & Information Technologies

Tags
facebook, wild, xss



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 07:12 PM.


Lebanon web design and development
Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Ad Management plugin by RedTyger
Share