<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: SuperPoke XSS Vulnerability</title>
	<atom:link href="http://theharmonyguy.com/2009/06/12/superpoke-injection-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://theharmonyguy.com/2009/06/12/superpoke-injection-vulnerability/</link>
	<description>Checking the security and privacy of social networking applications, white hat style...</description>
	<lastBuildDate>Thu, 11 Mar 2010 18:12:11 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: theharmonyguy</title>
		<link>http://theharmonyguy.com/2009/06/12/superpoke-injection-vulnerability/comment-page-1/#comment-5032</link>
		<dc:creator>theharmonyguy</dc:creator>
		<pubDate>Sat, 11 Jul 2009 01:44:27 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=91#comment-5032</guid>
		<description>@Sebastian: I&#039;m working now on a far less technical explanation of how these problems work.

As you can see from my site, I&#039;ve been tinkering with Facebook apps for quite a while.  I noticed that SuperPoke was using an insecure setup a while ago, but it wasn&#039;t that big a deal until Facebook introduced access to the API via JavaScript, which enabled my proof-of-concept exploit.</description>
		<content:encoded><![CDATA[<p>@Sebastian: I&#8217;m working now on a far less technical explanation of how these problems work.</p>
<p>As you can see from my site, I&#8217;ve been tinkering with Facebook apps for quite a while.  I noticed that SuperPoke was using an insecure setup a while ago, but it wasn&#8217;t that big a deal until Facebook introduced access to the API via JavaScript, which enabled my proof-of-concept exploit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sebastian Atudosie</title>
		<link>http://theharmonyguy.com/2009/06/12/superpoke-injection-vulnerability/comment-page-1/#comment-4828</link>
		<dc:creator>Sebastian Atudosie</dc:creator>
		<pubDate>Sat, 04 Jul 2009 22:16:20 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=91#comment-4828</guid>
		<description>Hi, I&#039;m just reading your stuff about facebook, and I&#039;m like &quot;WOW!&quot; I didn&#039;t know about all these things, but you use a lot of big words, can you please speak more.....easily to understand?

Anyway, how did you find out about these problems?</description>
		<content:encoded><![CDATA[<p>Hi, I&#8217;m just reading your stuff about facebook, and I&#8217;m like &#8220;WOW!&#8221; I didn&#8217;t know about all these things, but you use a lot of big words, can you please speak more&#8230;..easily to understand?</p>
<p>Anyway, how did you find out about these problems?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: meh</title>
		<link>http://theharmonyguy.com/2009/06/12/superpoke-injection-vulnerability/comment-page-1/#comment-4009</link>
		<dc:creator>meh</dc:creator>
		<pubDate>Sat, 13 Jun 2009 10:19:23 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=91#comment-4009</guid>
		<description>&quot;I thought it would not be wise to release details publicly given the significance of this attack&quot; haha yah, that&#039;s why you&#039;ve had such a response. This is mickey mouse garbage. Go &quot;superpoke&quot; your boyfriend, your not a &quot;security researcher&#039;.</description>
		<content:encoded><![CDATA[<p>&#8220;I thought it would not be wise to release details publicly given the significance of this attack&#8221; haha yah, that&#8217;s why you&#8217;ve had such a response. This is mickey mouse garbage. Go &#8220;superpoke&#8221; your boyfriend, your not a &#8220;security researcher&#8217;.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
