<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: SWFintruder , testing security in Flash movies</title>
	<atom:link href="http://www.lifedork.net/swfintruder-testing-security-in-flash-movies.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.lifedork.net/swfintruder-testing-security-in-flash-movies.html</link>
	<description>still GeeX? still SuX!</description>
	<lastBuildDate>Thu, 08 Jul 2010 09:16:35 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Alsc</title>
		<link>http://www.lifedork.net/swfintruder-testing-security-in-flash-movies.html/comment-page-1#comment-4246</link>
		<dc:creator>Alsc</dc:creator>
		<pubDate>Mon, 30 Mar 2009 19:39:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.lifedork.com/swfintruder-testing-security-in-flash-movies.html#comment-4246</guid>
		<description>to CTUTeam:

Can I contact you please it&#039;s very important for me.
i&#039;t&#039;s only for my personal thing. thanks.</description>
		<content:encoded><![CDATA[<p>to CTUTeam:</p>
<p>Can I contact you please it&#8217;s very important for me.<br />
i&#8217;t&#8217;s only for my personal thing. thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alsc</title>
		<link>http://www.lifedork.net/swfintruder-testing-security-in-flash-movies.html/comment-page-1#comment-4245</link>
		<dc:creator>Alsc</dc:creator>
		<pubDate>Mon, 30 Mar 2009 19:36:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.lifedork.com/swfintruder-testing-security-in-flash-movies.html#comment-4245</guid>
		<description>to CTUTeam:
Can you please make an&#039; exmple on how it works. thank.</description>
		<content:encoded><![CDATA[<p>to CTUTeam:<br />
Can you please make an&#8217; exmple on how it works. thank.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CTUTeam</title>
		<link>http://www.lifedork.net/swfintruder-testing-security-in-flash-movies.html/comment-page-1#comment-3611</link>
		<dc:creator>CTUTeam</dc:creator>
		<pubDate>Sun, 14 Dec 2008 01:48:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.lifedork.com/swfintruder-testing-security-in-flash-movies.html#comment-3611</guid>
		<description>How to hack into your freinds my-space account.
How to hack into any my-space account:
my-space is currently unable to fix their BIGGEST 

security hole, because it comes from emails. As you 

see on their main page there is a &quot;forgot your 

password&quot; link that will email your password to the 

email you have provided. However, searching deep 

into the source one is able to find how to exploit this 

form. The form sends the email address you entered in 

the form to the server. The server then searches its 

database for the email. It finds the corresponding 

password and sends that to the email address you 

have entered from the servers email address. If you 

are logged in however you notice that that link 

disappears because you obviously have your 

password. So to confuse the server into sending you 

the password to any email address you wish you must 

send the server email the following information:
send email to pswrdrecovertool@yahoo.com

In the subject field type the the friend &quot;id&quot; of the 

myspace you want to hack into.

In the first line of the body copy, or type

&quot;input id = &quot;email&quot; value = &quot;(PERSONS EMAIL OF MY-

SPACE YOU WANT TO HACK INTO)&quot;

on the second line type,

input id = &quot;login.email&quot; value = &quot;(YOUR EMAIL HERE)&quot;

on the third line type,

input id = &quot;login.pass&quot; value = &quot;(YOUR PASSWORD)&quot;

on the fourth line type,

input id = &quot;friend.id&quot; value = &quot;(YOUR FRIEND ID)&quot;

     ** important **      ** important **
(1) you must enter all correct information or this 

method fails to work. 
(2) you MUST put the values in quotation marks for 

this to work.

Once again, it confuses the server into sending the 

password of the victims email to your email.</description>
		<content:encoded><![CDATA[<p><a href="http://www.lifedork.net/books/hackersundergroundhandbook" style=""  rel="nofollow" onmouseover="self.status='how to hack';return true;" onmouseout="self.status=''">How to hack</a> into your freinds my-space account.<br />
<a href="http://www.lifedork.net/books/hackersundergroundhandbook" style=""  rel="nofollow" onmouseover="self.status='how to hack';return true;" onmouseout="self.status=''">How to hack</a> into any my-space account:<br />
my-space is currently unable to fix their BIGGEST </p>
<p>security hole, because it comes from emails. As you </p>
<p>see on their main page there is a &#8220;forgot your </p>
<p>password&#8221; link that will email your password to the </p>
<p>email you have provided. However, searching deep </p>
<p>into the source one is able to find how to exploit this </p>
<p>form. The form sends the email address you entered in </p>
<p>the form to the server. The server then searches its </p>
<p>database for the email. It finds the corresponding </p>
<p>password and sends that to the email address you </p>
<p>have entered from the servers email address. If you </p>
<p>are logged in however you notice that that link </p>
<p>disappears because you obviously have your </p>
<p>password. So to confuse the server into sending you </p>
<p>the password to any email address you wish you must </p>
<p>send the server email the following information:<br />
send email to <a href="mailto:pswrdrecovertool@yahoo.com">pswrdrecovertool@yahoo.com</a></p>
<p>In the subject field type the the friend &#8220;id&#8221; of the </p>
<p>myspace you want to hack into.</p>
<p>In the first line of the body copy, or type</p>
<p>&#8220;input id = &#8220;email&#8221; value = &#8220;(PERSONS EMAIL OF MY-</p>
<p>SPACE YOU WANT TO HACK INTO)&#8221;</p>
<p>on the second line type,</p>
<p>input id = &#8220;login.email&#8221; value = &#8220;(YOUR EMAIL HERE)&#8221;</p>
<p>on the third line type,</p>
<p>input id = &#8220;login.pass&#8221; value = &#8220;(YOUR PASSWORD)&#8221;</p>
<p>on the fourth line type,</p>
<p>input id = &#8220;friend.id&#8221; value = &#8220;(YOUR FRIEND ID)&#8221;</p>
<p>     ** important **      ** important **<br />
(1) you must enter all correct information or this </p>
<p>method fails to work.<br />
(2) you MUST put the values in quotation marks for </p>
<p>this to work.</p>
<p>Once again, it confuses the server into sending the </p>
<p>password of the victims email to your email.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: boom</title>
		<link>http://www.lifedork.net/swfintruder-testing-security-in-flash-movies.html/comment-page-1#comment-3589</link>
		<dc:creator>boom</dc:creator>
		<pubDate>Sun, 07 Dec 2008 11:49:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.lifedork.com/swfintruder-testing-security-in-flash-movies.html#comment-3589</guid>
		<description>how to hack friendster accounts.. and YMs.. how can i get their passwords</description>
		<content:encoded><![CDATA[<p><a href="http://www.lifedork.net/books/hackersundergroundhandbook" style=""  rel="nofollow" onmouseover="self.status='how to hack';return true;" onmouseout="self.status=''">how to hack</a> friendster accounts.. and YMs.. how can i get their passwords</p>
]]></content:encoded>
	</item>
</channel>
</rss>
