So my bud hacks facebook and gets offered a job

swtethan

Diamond Member
Aug 5, 2005
9,083
0
0
i predict a "my friend just got arrested for hacking thread" .... "he called me from jail"
 

SirChadwick

Diamond Member
Jul 27, 2001
4,595
1
81
I don't know the seriousness of what he did, but they didn't seem too worried about it.

We noticed you decided to exploit an XSS hole on our site that enabled you to load a custom css file. While this is very neat and basically harmless, the action you initiated to virally propagate the exploit had a bad side effect. Because you posted to contactinfo.php just the website field, you effectively blanked the other fields on the page for anyone who viewed your profile (cell phone, email, etc). We do not like to lose data, and neither do our users. In the future, if you find a security hole, please contact me directly, rather than just exposing it on the site.
 

chuckywang

Lifer
Jan 12, 2004
20,139
1
0
BTW, what does he mean when he said the accounts were getting "infected"? Was he doing anything that affects other people's facebook accounts?
 

Udel

Senior member
Sep 2, 2005
892
0
0
That was actually a good read. I don't think he will get in trouble for it honestly. The offer is probally legit.
 

Reel

Diamond Member
Jul 14, 2001
4,484
0
76
Some guys did that on myspace already. I wouldn't be surprised if your friend took the idea from there. XSS holes are way too prevalent in web applications. Most web applications I am paid to do a security assessment on suffer from this problem.

That was also how the avatar pictures were inserted on fusetalk a year or so ago. Lucky for AT, nobody was malicious with the code they inserted because they could have done some worse things with it.