<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2614744477359998094</id><updated>2011-07-28T16:47:30.148-07:00</updated><title type='text'>Facebook Application Smashing</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://defacebooked.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://defacebooked.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Standard Error</name><uri>http://www.blogger.com/profile/11165986954710659008</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>10</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2614744477359998094.post-2981349208898538526</id><published>2007-07-23T18:43:00.000-07:00</published><updated>2007-07-23T18:55:38.000-07:00</updated><title type='text'>Moods (Emoting)</title><summary type='text'>This one's very interesting. Moods is vulnerable to the typical problem that we've seen in the past. Mainly, viewing a non-friend's mood history. In order to check out someone's history, simply alter the following url.http://apps.facebook.com/emoting/?page=history&amp;uid=xxxxxxxxxObviously substituting the person's id for the uid variable.Now, here's the twist with this application. It doesn't even </summary><link rel='replies' type='application/atom+xml' href='http://defacebooked.blogspot.com/feeds/2981349208898538526/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2614744477359998094&amp;postID=2981349208898538526' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/2981349208898538526'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/2981349208898538526'/><link rel='alternate' type='text/html' href='http://defacebooked.blogspot.com/2007/07/moods-emoting.html' title='Moods (Emoting)'/><author><name>Standard Error</name><uri>http://www.blogger.com/profile/11165986954710659008</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2614744477359998094.post-3190218722533436363</id><published>2007-07-23T18:01:00.000-07:00</published><updated>2007-07-23T18:25:32.327-07:00</updated><title type='text'>My Greeting Cards</title><summary type='text'>*Yawns* Same thing. My Greeting Cards Allows you to send greeting cards to non-friends. Custom text can be sent along with the card as well.Click on My Greeting Cards application.Enter a friend's name.Change recipient_id value.Send gift</summary><link rel='replies' type='application/atom+xml' href='http://defacebooked.blogspot.com/feeds/3190218722533436363/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2614744477359998094&amp;postID=3190218722533436363' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/3190218722533436363'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/3190218722533436363'/><link rel='alternate' type='text/html' href='http://defacebooked.blogspot.com/2007/07/my-greeting-cards.html' title='My Greeting Cards'/><author><name>Standard Error</name><uri>http://www.blogger.com/profile/11165986954710659008</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2614744477359998094.post-2382936403713336035</id><published>2007-07-23T13:22:00.000-07:00</published><updated>2007-07-23T13:25:05.041-07:00</updated><title type='text'>Superlatives</title><summary type='text'>I'm seeing a trend here...  Superlatives allows you to make predictions about friends that others can vote on, like "so and so is most likely to sell their soul for a donut."  Cute.  Except you can predict about non-friends too.</summary><link rel='replies' type='application/atom+xml' href='http://defacebooked.blogspot.com/feeds/2382936403713336035/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2614744477359998094&amp;postID=2382936403713336035' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/2382936403713336035'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/2382936403713336035'/><link rel='alternate' type='text/html' href='http://defacebooked.blogspot.com/2007/07/superlatives.html' title='Superlatives'/><author><name>SerajewelKS</name><uri>http://www.blogger.com/profile/01012921717955823504</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2614744477359998094.post-5396017543359306668</id><published>2007-07-23T13:10:00.000-07:00</published><updated>2007-07-23T13:14:03.157-07:00</updated><title type='text'>Easter Egg</title><summary type='text'>Another non-friend attack.  Easter Egg lets you post messages on your profile that only certain friends can read.  Like other apps, you can trick it into leaving messages for people who aren't your friends.  Because it's on your profile there isn't much danger here, but the app will give you the option of sending a notice to the recipient.  They might not appreciate receiving messages from people</summary><link rel='replies' type='application/atom+xml' href='http://defacebooked.blogspot.com/feeds/5396017543359306668/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2614744477359998094&amp;postID=5396017543359306668' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/5396017543359306668'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/5396017543359306668'/><link rel='alternate' type='text/html' href='http://defacebooked.blogspot.com/2007/07/easter-egg.html' title='Easter Egg'/><author><name>SerajewelKS</name><uri>http://www.blogger.com/profile/01012921717955823504</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2614744477359998094.post-8232581353760791648</id><published>2007-07-22T20:13:00.000-07:00</published><updated>2007-07-22T20:20:01.869-07:00</updated><title type='text'>Poke Pro</title><summary type='text'>Poke Pro allows you to do any number of actions to a friend. At least, that's what it's supposed to allow. Poke Pro also allows you do do these events to anyone with the application in their profile... friend or not.Poking random peopleOn your own profile, enter the name of a friend in your Poke Pro box.Alter the id value to reflect the id of the person you wish to poke.Go!How annoying would it </summary><link rel='replies' type='application/atom+xml' href='http://defacebooked.blogspot.com/feeds/8232581353760791648/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2614744477359998094&amp;postID=8232581353760791648' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/8232581353760791648'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/8232581353760791648'/><link rel='alternate' type='text/html' href='http://defacebooked.blogspot.com/2007/07/poke-pro.html' title='Poke Pro'/><author><name>Standard Error</name><uri>http://www.blogger.com/profile/11165986954710659008</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2614744477359998094.post-4443816598299799452</id><published>2007-07-22T17:46:00.000-07:00</published><updated>2007-07-22T18:08:19.050-07:00</updated><title type='text'>Fun Wall</title><summary type='text'>The Fun Wall application has the same vulnerability as the aforementioned Super Wall application. You can post messages on a wall as another person.Exploiting the identity theft.Proceed to the target's profile.Enter the desired message into the Fun Wall form.Change fb_sig_user to the id of the person you wish to post as. (Firebug)Post.</summary><link rel='replies' type='application/atom+xml' href='http://defacebooked.blogspot.com/feeds/4443816598299799452/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2614744477359998094&amp;postID=4443816598299799452' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/4443816598299799452'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/4443816598299799452'/><link rel='alternate' type='text/html' href='http://defacebooked.blogspot.com/2007/07/fun-wall.html' title='Fun Wall'/><author><name>Standard Error</name><uri>http://www.blogger.com/profile/11165986954710659008</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2614744477359998094.post-3524568545111411815</id><published>2007-07-22T14:47:00.000-07:00</published><updated>2007-07-22T14:53:34.787-07:00</updated><title type='text'>Sticky Notes</title><summary type='text'>The Sticky Notes application contains a vulnerability that allows you to send a sticky note to any Facebook member, even if they aren't your friend.  The application description suggests that this is not the designer's intention.This can be exploited by writing a new note, and when you're asked to choose the recipients:Enter the name of one of your friends.Find the Facebook ID of the person you </summary><link rel='replies' type='application/atom+xml' href='http://defacebooked.blogspot.com/feeds/3524568545111411815/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2614744477359998094&amp;postID=3524568545111411815' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/3524568545111411815'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/3524568545111411815'/><link rel='alternate' type='text/html' href='http://defacebooked.blogspot.com/2007/07/sticky-notes.html' title='Sticky Notes'/><author><name>SerajewelKS</name><uri>http://www.blogger.com/profile/01012921717955823504</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2614744477359998094.post-3026996759992507436</id><published>2007-07-22T13:21:00.000-07:00</published><updated>2007-07-22T13:27:45.843-07:00</updated><title type='text'>Free Gifts</title><summary type='text'>Note: I highly suggest that you install Firebug for tweaking web pages. Facebook came out with a feature that allows you to give virtual gifts to your friends. Maybe you want to send a picture of a rose, a picture of a hamburger, or maybe a picture of handcuffs to your friend. That is all fine and dandy, but then Facebook decided to charge you $1 per gift. Most of us are too cheap to actually pay</summary><link rel='replies' type='application/atom+xml' href='http://defacebooked.blogspot.com/feeds/3026996759992507436/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2614744477359998094&amp;postID=3026996759992507436' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/3026996759992507436'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/3026996759992507436'/><link rel='alternate' type='text/html' href='http://defacebooked.blogspot.com/2007/07/free-gifts.html' title='Free Gifts'/><author><name>Standard Error</name><uri>http://www.blogger.com/profile/11165986954710659008</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2614744477359998094.post-3933146158433935323</id><published>2007-07-22T12:56:00.000-07:00</published><updated>2007-07-22T13:17:15.445-07:00</updated><title type='text'>Super Wall</title><summary type='text'>When you setup your Facebook account, you are given you a virtual "wall" where friends can post public comments to your profile. This is kind of cool, but there are some limitations. You cannot post an image or a video to a friend's wall. Well, the inventors of Super Wall have come to the rescue. This application allows simple text messages, picture messages, and even links to web videos served </summary><link rel='replies' type='application/atom+xml' href='http://defacebooked.blogspot.com/feeds/3933146158433935323/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2614744477359998094&amp;postID=3933146158433935323' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/3933146158433935323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/3933146158433935323'/><link rel='alternate' type='text/html' href='http://defacebooked.blogspot.com/2007/07/super-wall.html' title='Super Wall'/><author><name>Standard Error</name><uri>http://www.blogger.com/profile/11165986954710659008</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2614744477359998094.post-8385224342370495933</id><published>2007-07-22T12:43:00.000-07:00</published><updated>2007-07-22T12:55:53.783-07:00</updated><title type='text'>Introduction</title><summary type='text'>For those of you that have been clamoring about the addition of Facebook applications, we have decided to add more fuel to the fire. We have started exposing some of the additional problems (other than the sheer annoyance) introduced by adding third party code onto your Facebook page. Due to the overwhelming number of applications, we don't have time to check every application for security issues</summary><link rel='replies' type='application/atom+xml' href='http://defacebooked.blogspot.com/feeds/8385224342370495933/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2614744477359998094&amp;postID=8385224342370495933' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/8385224342370495933'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2614744477359998094/posts/default/8385224342370495933'/><link rel='alternate' type='text/html' href='http://defacebooked.blogspot.com/2007/07/introduction.html' title='Introduction'/><author><name>Standard Error</name><uri>http://www.blogger.com/profile/11165986954710659008</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
