<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!--Web 2.0 Content Powered by MyST Blogsite® (http://blogsite.com)-->
<!--A service of MyST Technology Partners, Inc. (http://myst-technology.com)-->
<?xml-stylesheet href="http://blog.cenzic.com/public/styles/etc/object.xsl" type="text/xsl"?>

<?myst-baseUrl http://blog.cenzic.com/public/?>

<MySmartChannels Public="true" UserID="202607" dT="178" t0="1283904445141">
     <GetChannelItem_Result>
      <Item>
       <Resource>
        <ObjectID>222842</ObjectID>
        <ObjectClass>Resource</ObjectClass>
        <OwnerID ObjectClass="Domain" Title="[Weblog] Web Application Security Insights">202615</OwnerID>
        <CreatedByID ObjectClass="User" Title="eswanson">202768</CreatedByID>
        <ModifiedByID ObjectClass="User" Title="eswanson">202768</ModifiedByID>
        <CreateTime Title="2009-01-05 21:13:43 EST">1231208023093</CreateTime>
        <ModifyTime Title="2009-01-09 21:44:08 EST">1231555448732</ModifyTime>
        <SecurityModel>Controlled</SecurityModel>
        <Name>Facebook Hacked Due to XSS Vulnerabilities</Name>
        <Summary>Facebook contains highly critical XSS vulnerabilities for hackers to exploit, posing privacy risks to users</Summary>
        <Description>&lt;p&gt;&lt;a href="http://www.xssed.com/news/80/New_highly_critical_Facebook_XSS_vulnerabilities_pose_serious_privacy_risks/"&gt;&lt;img alt="Facebook Hacked with XSS Vulnerabilities" hspace="10" src="http://www.cenzic.com/images/blog/facebook.jpg" align="right" vspace="10" border="0" /&gt;&lt;/a&gt;The XSSed site reported a series of highly critical XSS vulnerabilities on Facebook (&lt;a title="Facebook XSS flaws reported on Dec 15, 2008" href="http://www.xssed.com/news/80/New_highly_critical_Facebook_XSS_vulnerabilities_pose_serious_privacy_risks/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;December 15, 2008&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; and again on &lt;a title="Facebook XSS vulnerabilities reported on January 4, 2009" href="http://www.xssed.com/news/81/Facebooks_Reset_Password_page_suffers_major_XSS_flaw/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;January 4, 2009&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;) that hackers can exploit.&amp;nbsp; Various Facebook functionalities affected include the&amp;nbsp;new users registration page, iPhone login, reset password pages, and others.&amp;nbsp; &lt;/p&gt;&lt;p&gt;Malicious people can exploit these XSS bugs to infect millions of &lt;strong&gt;Facebook members with malware, adware and spyware&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;So far, Facebook has not fixed these flaws&lt;/strong&gt;, so be very careful when using your account by questioning suspicious requests and not accepting friend invites from people you don&amp;rsquo;t know.&amp;nbsp; &lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</Description>
        <ResourceTypeID ObjectClass="ResourceType" Title="Item:Link">9</ResourceTypeID>
        <ContentType>application/xml</ContentType>
        <ContentDocument>
         <ItemProperties>
               <CommonProperties>
                <Hidden>false</Hidden>

                <Keywords>
                 <Keyword>facebook</Keyword>

                 <Keyword>hack</Keyword>

       </Keywords>

                <Links>
                 <Link>
                  <Title>New highly critical Facebook XSS vulnerabilities pose serious privacy risks</Title>

                  <Synopsis>XSSed Site finds numerous XSS vulnerabilities on Facebook</Synopsis>

                  <URL>http://www.xssed.com/news/80/New_highly_critical_Facebook_XSS_vulnerabilities_pose_serious_privacy_risks/</URL>

        </Link>

                 <Link>
                  <Title>Facebook 'reset password' page suffers major XSS flaw</Title>

                  <Synopsis>XSSed Site finds numerous XSS vulnerabilities on Facebook</Synopsis>

                  <URL>http://www.xssed.com/news/81/Facebooks_Reset_Password_page_suffers_major_XSS_flaw/</URL>

        </Link>

       </Links>

      </CommonProperties>

               <RemoteInfo>
                <UserAgent>Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB5; .NET CLR 1.1.4322; .NET CLR 2.0.50727)</UserAgent>

                <RemoteHost>127.0.0.1</RemoteHost>

                <RemoteAddr>127.0.0.1</RemoteAddr>

                <RemoteUser>eswanson</RemoteUser>

                <ForwardedFor>64.60.123.45</ForwardedFor>

      </RemoteInfo>

     </ItemProperties>
        </ContentDocument>
       </Resource>
       <Shares/>
       <Subjects/>
       <UserPermissions>
        <CanDelete>false</CanDelete>
        <CanDiscover>true</CanDiscover>
        <CanEdit>false</CanEdit>
        <CanEditPermissions>false</CanEditPermissions>
        <CanRead>true</CanRead>
       </UserPermissions>
       <CommentInfo>
        <CommentChannelRef AllowAnonymous="true" Inherited="true">
         <ChannelID ObjectClass="Channel" Title="[Public] Public Comments">204329</ChannelID>
         <UserPermissions>
          <CanCreateChannelItem>false</CanCreateChannelItem>
          <CanDelete>false</CanDelete>
          <CanDiscover>true</CanDiscover>
          <CanEdit>false</CanEdit>
          <CanEditPermissions>false</CanEditPermissions>
          <CanPublish>false</CanPublish>
          <CanRead>true</CanRead>
         </UserPermissions>
        </CommentChannelRef>
        <Comments>
         <Comment>
          <Item>
           <Resource>
            <ObjectID>223096</ObjectID>
            <ObjectClass>Resource</ObjectClass>
            <OwnerID ObjectClass="Domain" Title="[Public] Public Comments">204329</OwnerID>
            <CreatedByID ObjectClass="User" Title="$Anonymous">173239</CreatedByID>
            <ModifiedByID ObjectClass="User" Title="eswanson">202768</ModifiedByID>
            <CreateTime Title="2009-01-07 19:39:51 EST">1231375191290</CreateTime>
            <ModifyTime Title="2009-01-08 12:05:32 EST">1231434332492</ModifyTime>
            <SecurityModel>Controlled</SecurityModel>
            <Name>Who Cares</Name>
            <Summary>Who cares if your facebook account is hacked?</Summary>
            <Description>So what if someones facebook account is hacked. By now they should know better than to put personal information on their facebook account. Rule of thumb, if you don't want your mom to know then don't put it on facebook.</Description>
            <ResourceTypeID ObjectClass="ResourceType" Title="Item:Content">10</ResourceTypeID>
            <ContentType>application/xml</ContentType>
            <ContentDocument>
             <ItemProperties>
                   <CommonProperties>
       
                   <Hidden>false</Hidden>
            </CommonProperties>

                  <ns3:Details xmlns="urn:MyST-Technology.Structured.Details" xmlns:ns3="urn:MyST-Technology.Structured.Details">
                   <ns3:Collection name="Michael Morano" type="urn:MyST-Technology.Structured.Collection.Contact">
                    <ns3:Attribute name="EMail" type="email" value="michael.morano@soundassurance.com"/>

                    <ns3:Attribute name="Web" type="url" value=""/>

                    <ns3:Attribute name="Twitter" type="twitter" value=""/>

       </ns3:Collection>

      </ns3:Details>

                  <RemoteInfo>
                   <UserAgent>Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5</UserAgent>

                   <RemoteHost>127.0.0.1</RemoteHost>

                   <RemoteAddr>127.0.0.1</RemoteAddr>

                   <ForwardedFor>24.250.48.153</ForwardedFor>

      </RemoteInfo>

     </ItemProperties>
           </ContentDocument>
          </Resource>
          <UserPermissions>
           <CanDelete>false</CanDelete>
           <CanDiscover>true</CanDiscover>
           <CanEdit>false</CanEdit>
           <CanEditPermissions>false</CanEditPermissions>
           <CanRead>true</CanRead>
          </UserPermissions>
          <CommentInfo>
           <CommentChannelRef>
            <ChannelID/>
           </CommentChannelRef>
           <Comments/>
          </CommentInfo>
         </Item>
        </Comment>
       </Comments>
      </CommentInfo>
      <Views>
       <SourceID ObjectClass="Channel" Title="[Weblog] Web Application Security Insights">202615</SourceID>

              <View>
               <Name>blog</Name>

               <Model>blogsite/Cenzic/web</Model>

               <Style/>

               <Scheme/>

       </View>

              <View>
               <Name>edit-item</Name>

               <Model>blogsite/Cenzic/right-content</Model>

               <Style/>

               <Scheme/>

       </View>

              <View>
               <Name>left</Name>

               <Model>blogsite/Cenzic/left-content</Model>

               <Style/>

               <Scheme/>

       </View>

              <View>
               <Name>right</Name>

               <Model>blogsite/Cenzic/right-content</Model>

               <Style/>

               <Scheme/>

       </View>

              <View>
               <Name>wide</Name>

               <Model>blogsite/Cenzic/wide-content</Model>

               <Style/>

               <Scheme/>

       </View>

      </Views>
       <Views>
        <SourceID ObjectClass="Channel" Shared="true" Title="[Public] What's New">202621</SourceID>

               <View>
                <Name>blog</Name>

                <Model>blogsite/Cenzic/whatsnew</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>edit-item</Name>

                <Model>blogsite/Cenzic/right-content</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>left</Name>

                <Model>blogsite/Cenzic/left-content</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>right</Name>

                <Model>blogsite/Cenzic/right-content</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>wide</Name>

                <Model>blogsite/Cenzic/wide-content</Model>

                <Style/>

                <Scheme/>

       </View>

      </Views>
       </Item>
      </GetChannelItem_Result>
     </MySmartChannels>
