February 08, 2014

XSS Vulnerability found in Facebook Subdomain

Today this is second biggest vulnerability found by hackers, New XSS(cross site scripting) vulnerability found on Facebook subdomain (https://developers.facebook.com/). This is discovered by  Mauritania_Attacker (AnonGhost)


Cross-site scripting (XSS) is a type of computer security vulnerability typically found in Web applications. XSS enables attackers to inject client-side script into Web pages viewed by other users.



Hacker added the below text in the subdomain.


for (;;);{"__ar":1,"payload":{"redirect":"\/0wn3d_By_Mauritania_Attacker(AnonGhost)&__a=1\/"},"bootloadable":{},"ixData":[]}

Last month Facebook paid the $33,500  for the bug bounty program, let see Facebook how much pay for this vulnerability to Hacker.

Vulnerable URL :: 
https://developers.facebook.com/0wn3d_By_Mauritania_Attacker(AnonGhost)&__a=1

Mirror URL : http://aljyyosh.org/mirror.php?id=103373

Today morning @TheBreShiE hacker found the XSS vulnerability on Tumblr website.



Author Venkatesh Yalagandula Follow us Google + and Facebook and Twitter

 
Design by Lasantha
DMCA.com