<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: SuperPoke XSS Vulnerability</title>
	<atom:link href="http://theharmonyguy.com/2009/06/12/superpoke-injection-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://theharmonyguy.com/2009/06/12/superpoke-injection-vulnerability/</link>
	<description>Investigating privacy and security issues in online social networking</description>
	<lastBuildDate>Thu, 09 Feb 2012 10:47:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: theharmonyguy</title>
		<link>http://theharmonyguy.com/2009/06/12/superpoke-injection-vulnerability/comment-page-1/#comment-5032</link>
		<dc:creator>theharmonyguy</dc:creator>
		<pubDate>Sat, 11 Jul 2009 01:44:27 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=91#comment-5032</guid>
		<description>@[comment removed]: I&#039;m working now on a far less technical explanation of how these problems work.

As you can see from my site, I&#039;ve been tinkering with Facebook apps for quite a while.  I noticed that SuperPoke was using an insecure setup a while ago, but it wasn&#039;t that big a deal until Facebook introduced access to the API via JavaScript, which enabled my proof-of-concept exploit.</description>
		<content:encoded><![CDATA[<p>@[comment removed]: I&#8217;m working now on a far less technical explanation of how these problems work.</p>
<p>As you can see from my site, I&#8217;ve been tinkering with Facebook apps for quite a while.  I noticed that SuperPoke was using an insecure setup a while ago, but it wasn&#8217;t that big a deal until Facebook introduced access to the API via JavaScript, which enabled my proof-of-concept exploit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: meh</title>
		<link>http://theharmonyguy.com/2009/06/12/superpoke-injection-vulnerability/comment-page-1/#comment-4009</link>
		<dc:creator>meh</dc:creator>
		<pubDate>Sat, 13 Jun 2009 10:19:23 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=91#comment-4009</guid>
		<description>&quot;I thought it would not be wise to release details publicly given the significance of this attack&quot; haha yah, that&#039;s why you&#039;ve had such a response. This is mickey mouse garbage. Go &quot;superpoke&quot; your boyfriend, your not a &quot;security researcher&#039;.</description>
		<content:encoded><![CDATA[<p>&#8220;I thought it would not be wise to release details publicly given the significance of this attack&#8221; haha yah, that&#8217;s why you&#8217;ve had such a response. This is mickey mouse garbage. Go &#8220;superpoke&#8221; your boyfriend, your not a &#8220;security researcher&#8217;.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

