RockYou’s Emote on Plaxo

Date: Friday, November 2, 2007

Initial hack: 45 minutes

Vulnerabilities:

  • Able to change current Emote status for any user
  • Able to access Emote history and current status for any user
  • Able to insert HTML, including JavaScript, into Emote pages

Coverage: TechCrunch

Progress: Plaxo has removed Emote from their whitelist.  As of Nov. 6, Emote remains unpatched.

8 Responses to “RockYou’s Emote on Plaxo”

  1. OpenSocial Hacked Again Says:

    [...] now has a blog up where he is writing about his hacks of OpenSocial applications. See it here. He notes that RockYou’s application remains [...]

  2. Ajax Girl » Blog Archive » OpenSocial Hacked Again Says:

    [...] now has a blog up where he is writing about his hacks of OpenSocial applications. See it here. He notes that RockYou’s application remains [...]

  3. Jean-Marie Le Ray Says:

    Hi HarmonyGuy,

    Well done! Who better than you would be able to build a wonderful app for Facebook and OpenSocial.
    If you’re interested, you can contact me by email, I’ve got an app idea and ‘m searching for a developer.
    Best regards,
    Jean-Marie

  4. NexGen Technology Blog » OpenSocial Hacked Again Says:

    [...] now has a blog up where he is writing about his hacks of OpenSocial applications. See it here. He notes that RockYou’s application remains [...]

  5. salman Says:

    You are obviously a very skilled developer. I am looking to build applications for my website for facebook and open social networking. Looking forward to hearing from you soon.

  6. OpenSocial Hacked Again | GOSSIP Says:

    [...] now has a blog up where he is writing about his hacks of OpenSocial applications. See it here. He notes that RockYou’s application remains [...]

  7. OpenSocial Hacked Again at Geekstr Says:

    [...] now has a blog up where he is writing about his hacks of OpenSocial applications. See it here. He notes that RockYou’s application remains [...]

  8. omar Says:

    now it’s at myspace x.x.. Heroes apps

Leave a Reply

Checking the security and privacy of social networking applications, white hat style…