<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: New Utility Allows You to Control Facebook Accounts Without the Password</title>
	<atom:link href="http://doteduguru.com/id3831-new-utility-allows-you-to-control-facebook-accounts-without-the-password.html/feed" rel="self" type="application/rss+xml" />
	<link>http://doteduguru.com/id3831-new-utility-allows-you-to-control-facebook-accounts-without-the-password.html</link>
	<description>Internet Marketing and Web Development in Higher Education and other tidbits...</description>
	<lastBuildDate>Thu, 18 Mar 2010 18:49:07 -0400</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Sample Resumes</title>
		<link>http://doteduguru.com/id3831-new-utility-allows-you-to-control-facebook-accounts-without-the-password.html/comment-page-1#comment-8936</link>
		<dc:creator>Sample Resumes</dc:creator>
		<pubDate>Fri, 30 Oct 2009 19:32:17 +0000</pubDate>
		<guid isPermaLink="false">http://doteduguru.com/?p=3831#comment-8936</guid>
		<description>Oh wow! its amazing. I hope that it &#039;ll be a very good function to the users. I don&#039;t know about it. Thanks a lot for sharing such a nice post.</description>
		<content:encoded><![CDATA[<p>Oh wow! its amazing. I hope that it &#8216;ll be a very good function to the users. I don&#8217;t know about it. Thanks a lot for sharing such a nice post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Web Solutions</title>
		<link>http://doteduguru.com/id3831-new-utility-allows-you-to-control-facebook-accounts-without-the-password.html/comment-page-1#comment-8891</link>
		<dc:creator>Web Solutions</dc:creator>
		<pubDate>Mon, 26 Oct 2009 07:00:52 +0000</pubDate>
		<guid isPermaLink="false">http://doteduguru.com/?p=3831#comment-8891</guid>
		<description>It will be really good if works well according to the user needs</description>
		<content:encoded><![CDATA[<p>It will be really good if works well according to the user needs</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: theharmonyguy</title>
		<link>http://doteduguru.com/id3831-new-utility-allows-you-to-control-facebook-accounts-without-the-password.html/comment-page-1#comment-8804</link>
		<dc:creator>theharmonyguy</dc:creator>
		<pubDate>Wed, 21 Oct 2009 21:45:59 +0000</pubDate>
		<guid isPermaLink="false">http://doteduguru.com/?p=3831#comment-8804</guid>
		<description>Correction to my correction: As Paul pointed out to me via Twitter, an attacker could theoretically change document.domain. But Facebook filters any JavaScript in an application running via apps.facebook.com, so they wouldn&#039;t allow such code via an app XSS hole, and the attack would still fail.</description>
		<content:encoded><![CDATA[<p>Correction to my correction: As Paul pointed out to me via Twitter, an attacker could theoretically change document.domain. But Facebook filters any JavaScript in an application running via apps.facebook.com, so they wouldn&#8217;t allow such code via an app XSS hole, and the attack would still fail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: theharmonyguy</title>
		<link>http://doteduguru.com/id3831-new-utility-allows-you-to-control-facebook-accounts-without-the-password.html/comment-page-1#comment-8802</link>
		<dc:creator>theharmonyguy</dc:creator>
		<pubDate>Wed, 21 Oct 2009 21:35:17 +0000</pubDate>
		<guid isPermaLink="false">http://doteduguru.com/?p=3831#comment-8802</guid>
		<description>Paul corrected me that you could actually change document.domain if you could run pure JavaScript on an apps.facebook.com. But code on that domain is filtered by Facebook, so inserting script that tries to change document.domain would not be rendered.

So, exploiting an application would still not work, but for a different reason. Thanks for the clarification, Paul.</description>
		<content:encoded><![CDATA[<p>Paul corrected me that you could actually change document.domain if you could run pure JavaScript on an apps.facebook.com. But code on that domain is filtered by Facebook, so inserting script that tries to change document.domain would not be rendered.</p>
<p>So, exploiting an application would still not work, but for a different reason. Thanks for the clarification, Paul.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: theharmonyguy</title>
		<link>http://doteduguru.com/id3831-new-utility-allows-you-to-control-facebook-accounts-without-the-password.html/comment-page-1#comment-8801</link>
		<dc:creator>theharmonyguy</dc:creator>
		<pubDate>Wed, 21 Oct 2009 20:58:14 +0000</pubDate>
		<guid isPermaLink="false">http://doteduguru.com/?p=3831#comment-8801</guid>
		<description>Thanks for the link!

Slight correction, though: Since Facebook runs all applications on the apps.facebook.com domain, an XSS hole in an application would not allow you to grab the cookies for facebook.com or www.facebook.com - at least not in any modern browser I know of.

Of course, you can send links to other users with an application XSS hole by using the Facebook API.</description>
		<content:encoded><![CDATA[<p>Thanks for the link!</p>
<p>Slight correction, though: Since Facebook runs all applications on the apps.facebook.com domain, an XSS hole in an application would not allow you to grab the cookies for facebook.com or <a href="http://www.facebook.com" rel="nofollow">http://www.facebook.com</a> &#8211; at least not in any modern browser I know of.</p>
<p>Of course, you can send links to other users with an application XSS hole by using the Facebook API.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
