<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Social Security 101: Query Strings</title>
	<atom:link href="http://theharmonyguy.com/2008/02/01/social-application-security-101-query-strings/feed/" rel="self" type="application/rss+xml" />
	<link>http://theharmonyguy.com/2008/02/01/social-application-security-101-query-strings/</link>
	<description>Checking the security and privacy of social networking applications, white hat style...</description>
	<lastBuildDate>Sun, 14 Mar 2010 04:32:43 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Who and Where are those early Facebook people? &#171; Traveling Bits and Bytes</title>
		<link>http://theharmonyguy.com/2008/02/01/social-application-security-101-query-strings/comment-page-1/#comment-1076</link>
		<dc:creator>Who and Where are those early Facebook people? &#171; Traveling Bits and Bytes</dc:creator>
		<pubDate>Mon, 15 Dec 2008 17:32:16 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/2008/02/01/social-application-security-101-query-strings/#comment-1076</guid>
		<description>[...] here&#8217;s an article that discusses the security hole caused by this (i think, i just scanned it).      Posted by [...]</description>
		<content:encoded><![CDATA[<p>[...] here&#8217;s an article that discusses the security hole caused by this (i think, i just scanned it).      Posted by [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Social Hacking &#187; Blog Archive &#187; Social Me Still Too Social</title>
		<link>http://theharmonyguy.com/2008/02/01/social-application-security-101-query-strings/comment-page-1/#comment-310</link>
		<dc:creator>Social Hacking &#187; Blog Archive &#187; Social Me Still Too Social</dc:creator>
		<pubDate>Wed, 16 Jul 2008 19:27:11 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/2008/02/01/social-application-security-101-query-strings/#comment-310</guid>
		<description>[...] And it&#8217;s not even a POST request - I just enter a certain URL in my browser with a few query strings modified accordingly.  The server does nothing to validate who is making the request.  It reminds [...]</description>
		<content:encoded><![CDATA[<p>[...] And it&#8217;s not even a POST request &#8211; I just enter a certain URL in my browser with a few query strings modified accordingly.  The server does nothing to validate who is making the request.  It reminds [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Social Hacking &#187; Blog Archive &#187; Social Security 102: Client-Side Code</title>
		<link>http://theharmonyguy.com/2008/02/01/social-application-security-101-query-strings/comment-page-1/#comment-87</link>
		<dc:creator>Social Hacking &#187; Blog Archive &#187; Social Security 102: Client-Side Code</dc:creator>
		<pubDate>Mon, 11 Feb 2008 16:44:30 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/2008/02/01/social-application-security-101-query-strings/#comment-87</guid>
		<description>[...] Second in a series.  First post: Query Strings [...]</description>
		<content:encoded><![CDATA[<p>[...] Second in a series.  First post: Query Strings [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Social Hacking &#187; Blog Archive &#187; Facebook Application History Pages</title>
		<link>http://theharmonyguy.com/2008/02/01/social-application-security-101-query-strings/comment-page-1/#comment-84</link>
		<dc:creator>Social Hacking &#187; Blog Archive &#187; Facebook Application History Pages</dc:creator>
		<pubDate>Mon, 04 Feb 2008 08:14:02 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/2008/02/01/social-application-security-101-query-strings/#comment-84</guid>
		<description>[...] thought I would go ahead and do a combined post about an issue I keep encountering.  In my post on query strings, I noted that applications with some sort of history page are susceptible to a privacy problem if [...]</description>
		<content:encoded><![CDATA[<p>[...] thought I would go ahead and do a combined post about an issue I keep encountering.  In my post on query strings, I noted that applications with some sort of history page are susceptible to a privacy problem if [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Inside Facebook &#187; Many Facebook apps lack simple security checks</title>
		<link>http://theharmonyguy.com/2008/02/01/social-application-security-101-query-strings/comment-page-1/#comment-81</link>
		<dc:creator>Inside Facebook &#187; Many Facebook apps lack simple security checks</dc:creator>
		<pubDate>Sun, 03 Feb 2008 09:30:56 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/2008/02/01/social-application-security-101-query-strings/#comment-81</guid>
		<description>[...] hacker&#8221; theharmonyguy, who has identified security lapses in some of the most widely used Facebook and OpenSocial [...]</description>
		<content:encoded><![CDATA[<p>[...] hacker&#8221; theharmonyguy, who has identified security lapses in some of the most widely used Facebook and OpenSocial [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
