Facebook poked by XSS flaw
Good news #
Posted Saturday 24th May 2008 00:04 GMT
I tried every one of his PoCs, and even though I have facebook domains allowed in NoScript, it still spotted that they were XSS and blocked 'em.
FTW!
I second that #
Posted Monday 26th May 2008 08:25 GMT
Mozilla + NoScript and NoSquint (auto text size) = Bliss :-)
They're both "how did I live without them?!?" grade add-ons.
419 on LinkedIn #
Posted Tuesday 27th May 2008 02:26 GMT
I received a 419 scam message on LinkedIn a few months ago. I notified LinkedIn of it and to their credit they replied within 24 hours saying that they would investigate and delete the user account if it was found to be fraudulent.
As for the NoScript add-on, I agree it's great but that doesn't excuse shoddy coding! Perharps El Reg could point Facebook to this page: http://www.owasp.org/index.php/Top_10_2007-A1 ?
What about the look alike banners. #
Posted Tuesday 27th May 2008 15:03 GMT
While we are at it I'd like to point out (Facebook in particular from my experience) freely allow the look alike banners that contain the/or similar user interface as the rest of the site and word their banners as such that it appears as they are part of the intended interface function/application. But in fact lead you to an unwanted location outside of the Facebook.com domain.
This to me is 100% malicious and the sites apparent support for it is juts as malicious. No way anyone will convince me that is responsible advertising.
If someone has to trick a user to access their site then they are acting in a malicious manner. It's unacceptable and unforgivable.
- Paris because she would know better!
Sign up, sign up for The Register's weekly IT security newsletter - click here
Popular Whitepapers
- Thermal design of the Dell PowerEdge T610, R610, and R710 servers
Monolithic thermal design overview - Seven ways to optimize VMware server virtualization
Virtualized storage complimenting virtualized applications - Automating the Acquisition Process with Enterprise Level CRM
Sales Force Automation buyer’s guide - Checklist: Midmarket ERP Solutions
Control your rising business costs - Checklist: signs you need to upgrade your business phone system
Adopting the latest innovations in communication technology - Best practices for optimizing performance and availability in virtual infrastructures
Solutions for the complete physical and virtualized IT infrastructure



