[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CAMzomHkHb=KNO4OKvyLjFWk8hNkMTx-Fb2gDPfRY5Kt8pUcL7w@mail.gmail.com>
Date: Mon, 2 Jan 2012 12:45:28 -0800
From: t0hitsugu <tohitsugu@...il.com>
To: full-disclosure@...ts.grok.org.uk
Subject: facebook
anyone else notice the apps.facebook.com/<whatever> tend to be prone to sql
vulns? ie,
https://apps.facebook.com/worldwide_dev/ while not logged in, and
https://apps.facebook.com/worldwide_dev/%00
Due to them being apps, facebook I believe is not responsible for any
security issues, but in this case there is no dev listed. odd.
Content of type "text/html" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists