Collected research
Exploiting Facebook Application XSS Holes to Make API Requests
The Month of Facebook Bugs Report
Closing report of the Month of Facebook Bugs, which found XSS in over 9,700 Facebook applications. Because an application's page carries its session secret, an XSS there becomes an API request forgery: a double-injection trick loads the direct FBML page in an fb:iframe so a nested iframe leaks the secret via the referrer, enabling profile theft and viral posting.
Record
- Document
- The Month of Facebook Bugs Report
- Researcher
- theharmonyguy
- Published by
- theharmonyguy.com
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of theharmonyguy, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .