Very cool. Reminds me of a few years back when I was writing apps for facebook..along with there fan pages. They had there own markup language 'fbml' and 'fbjs'. The app was executed in a sandbox inside an iframe, which you could add as a tab on a fan page as well. A few times I broke thru there sandbox, allowing me to run any xss on page load, even on the fan page...it grabbed there token and added friends, invited a random number or friends to a fan page, likes fan pages, then post a status update...all random, nd it would base it on how many friends the user had. Anyway, a big problem was other developers stealing my code thnx to it being JS...So I ended up using every bug in JS like this, to confuse. I made a function that would pull element names/type/src etc, then used that as a alphanumeric definition. So my source had no spelt out names...on top of using JS hacks..then finally obfuscating. I rmbr the last time I did this and released it into the wild..it was patched up by FB in the morning after it sent to a security researcher who posted on his popular site for his audience to reverse engineer, which they did in a few hours...everything but the few lines that was passed to fb's sandbox that returned the broken code which enabled me to run the xss.... Gooooood times...javascript is fun#!
HN user
txt
user: you= me: -txt Asking for our real nick or handle or screenname whatever you wanna call it....
I was just chatting with some girl about this..Back in my AOL days you would get hit with the 'YOU=' or 'U=' as soon as you entered a chat. Mostly because we had thousands of aol logins and was always on a different account.
I use to service pools back in high school on the north shore of long island. And I remember doing Simons house, unbelievable property. The house keepers house was 5x bigger then mine..and the pool was massive, right on the edge of a cliff overlooking the long island sound. Sry if its offtopic but this read made me think of it!
Myspace had alot of issues when it came to security. At one point I was discovering multiple exploits every week that gave me access to any account I wanted. Most were patched up in a few days, using some temp workaround that would end up creating a new hole to explore lol, it was the wild west for me. Now I never used it to pull sensitive data or any type of illegal activities such as fraud etc..BUT I may have had quite a few sites that suddenly had millions of active users browsing them. ;] Im sure if I hopped on some of my old machines, I could post some interesting code from those days...
+1 ..I've been buying coffee recently from 7-11 in the morning, and I noticed there credit card swiper UI. When I use my debit card, ive always used 'credit' not debit, and im sure a huge % of people do the same, and here are the steps... Swipe card Is this a debit card? Y/N I Click No Do you want cash back? Y/N I Click No Then you must click cancel to run to bring up credit option ( but no instructions to do so) Then click credit, then click okay to the amount. Then its finally completes the purchase.. now each step takes a few seconds after each click, and you must use there stylus because just usingyour fingers wont work! I know this is a random comment, but UI related and ivd just noticed this recently, every 711 here on long island has the same machines! It doesnt seem like alot of steps but i bet the lines would move alot faster if they tweaked the UI a tiny bit!
I would add investing in precious metals to that list. Especially silver and gold right now. Its been extremely undervalued, and steadily moving sideways. When this stock market tanks even more then it has the last few weeks, we are going to see metals sky rocket like it has in the past. Gold and silver are an indispensable long-term inflation hedge. Look at jpmorgan, they were shorting silver for how long, now they are going long buying almost 2million ozs a day, i think they are up to over 750million ozs. All the central banks are buying up as much as they can get there hands on, so id say its a safe move to use a % of your savings and buy physical silver and gold. Im staying away from the paper precious metals investments, because if we do have a financial melt down, at least i know ill have some of my savings in my physical possession. ;]
Cool article. Ive done alot of specialty flooring jobs in the city and have been in some amazing buildings. They forgot to mention the amount of service elevators that are required to have a operator. My favorite was 20 broadway, rockafella standard oil building. There service elevator was 100+ years old, you could maybe fit 4 people in it. You have to take 1 elevator down then walk accross a super creepy basement with random staircases that lead to arch doorways of brick, broken concrete.Really cool stuff. The operator was a real bundle of joy too. If you juiced him, he would get you and your tools up before anybody else, ive seen this quite a few times. The floor i was working on too was intresting, it was a old lawyers office, there was an illumaniti triangle designed in the orginal concrete from 1928, and they made a big deal about not touching it the entire project (it was cracked, had holes) I ended up repairing it on one of the last days.
Bravo, took all the words out of my head!
Duncan Trussell Family Hour, Its All Happening - Zach Leary, Radiolab, Tangentially Speaking with Dr Christopher Ryan, The Dr Drew Show, The Joe Rogan Experience, WTF Podcast, Ari Shaffir's Skeptic Tank, MAPS Podcast,
These are all A+ Podcasts.
Today I got an email from a female friend of mine who passed away 4 years ago. Apparently they used her facebook info (email, display name) with the subject being 'Fwd for 'my facebook display name' followed by terrible spam .. Ohhhhh how I long for the days that we weren't hooked on social media.
Awesome link! I found one of my programs from back then! It was a 'baiter'. It would login to a few aol accounts, collect screennames from whos chatting lists. Then send them all instant messages with IMS_OFF setting off so a normal user wouldn't be able to respond back, only a aol employee. Then we would crack those screennames and do whatever it is we did back then lol. Mostly people used this for spamming though, it was one of the first released instant message spammer that could login multiple names. Hehe I miss those days! check out the intro art and interface. http://justinakapaste.com/sharkbait-v2/
I haven't made up my mind yet what to do with it but you know there are some ways of being evil without so much evil. ;]
Im getting it on the same domain, but the request can be sent from any domain, as long as the user is logged in. And yeah, but they aren't offering anything that would be worth the time.
Im getting it on the same domain, but the request can be sent from any domain, as long as the user is logged in.
Adding a extra token for protection against CSRF attacks will only work if is changed on each request. Some of the biggest sites out there do not do this. I know of one site in particular (I won't name it, but its HUGE) that generates a unique token every time a user logs in. The token doesn't change until the user logs out even if the user closes the browser and doesn't go back to the site for a week, the token will be the same. So it does its job, until somebody like me pokes around and finds a hole that will parse out that token, and generate a form that can make any request on behalf of that user in a iframe without that user knowing a thing. Evil yes, but I found this months ago, and it still works..and I haven't used it in anyway, besides a proof of concept.
+1.. I too, started with c64 and feel like I wouldn't be where I am at today if it wasn't for that. I use to take existing games and play with the graphics just to learn.
Nice clean cut site..I have a few suggestions to separate you guys from the others...I would make a 'bookmarklet', a few lines of js, that will spawn a input box asking for artist/track..OR the script can manipulate the current page they are on now, by copying what they have selected, because I know alot of people including myself, who see part of a lyric from a site, or facebook, and want to find the rest....Make a nice image, with the script as the url, and instructions for the user to drag it to there bookmarks toolbar so they can search even if they aren't at your site..Also, just as buro9 was saying..... Song Meanings/Interpretations/Understanding... People LOVE this, and here is a great example of it-> Say 'Harry & Sally' start dating..They both go to each of there homes after there date... and sally decides to post a song on her facebook about how she feels at that moment...Now Harry is wondering if this girl is really diggin him, or looking for a serious relationship etc..So over at his house, harry logs on facebook and sees that sally just posted a song just after ther date!!! What's harry going to do??? Look up those lyrics! And he might not completely understand the meaning of the song so he looks at what others have interpreted the song as...he now sees that sally doesnt want him to speak, she knows what hes feeling... (no doubt) lol just kidding but really, crazy example...I know first hand that this goes on alot..aha but anyway, ill post some more ideas soon!
Hey, I actually took a train from long island to the city this morning expecting to take a tour of 'general assembly', (where this hackathon was hosted)..But I didnt get past the elevator because of the hackathon! I wish I had known because I would have love to have been there coding with u iqster! Anyway, I plan on becoming a communal member there next month after they review the thousands of applications they have recieved.. iqster, did you get a chance to talk to any of the founders of general assembly there or anyone that is a member?? I talked to Matt Brimer for 5 mins next to the elevator, he couldn't sit down and talk with me because of the hackathon! I was planning on taking a tour and joining today but BLEHH! Do you have aim or skype iqster?
" following a telephone survey of 1,000 "likely voters." "
I actually enjoy working with facebook's open graph api, BUT Using the PHP & JS SDK is a nightmare. I wrote my own class in PHP using curl, all data is returned in JSON which for me makes things simple. Retrieving the access token and authenticating each user can be handled a number of ways. Ever since they updated there policies, you are now allowed to store all of the users info once they allow your "application". I've seen alot of people complain when they use the new SDK's, but I see no reason to go that route...I think the best way whether it be a application,fan page, or external site is to present your app first, let the user actually see it and not FORCE them to allow it (which 90% of most apps do)...Once they peform a action, either redirect/ or popup/iframe to the authorization url;. I use the 'offline' permission so the access token for each user doesn't expire. Once they allow it, pull any info you want by a simple curl request, then store all there info(including access token) in your DB. Simple as that! There are only a few things I dislike, there like/comment buttons, and how you are limited to using either there iframe or xfbml (which is still an iframe).
* More than 500 million active users
* 50% of our active users log on to Facebook in any given day
* Average user has 130 friends
* People spend over 700 billion minutes per month on Facebook
# More than one million developers and entrepreneurs from more than 180 countries
# Every month, more than 70% of Facebook users engage with Platform applications
# More than 550,000 active applications currently on Facebook Platform
# More than one million websites have integrated with Facebook Platform
# More than 150 million people engage with Facebook on external websites every month
# Two-thirds of comScore’s U.S. Top 100 websites and half of comScore’s Global Top 100 websites have integrated with Facebookhttp://www.facebook.com/press/info.php?statistics
They aren't going anywhere for awhile, this is exactly why I've spent so much time developing apps JUST for FB.
Hahaha this is exactly why I clicked this article..I saw the name patandjk and thought holy crap I haven't heard that since the beautiful days of AOL.. I remember using there API generator while learning to code in vb6...I think everybody had a copy back then..Boy does that bring back memories....
Wow, I have created a monster. I didn't create this javascript code to be used with promoting malware/viruses. Jesus christ, I love how people ruin everything.
Hey...when I purchased my 1st generation iPhone the 2nd week it came out, I jailbroke it and had Apache + php installed on it. I was then writing & running scripts locally. After awhile I found a decent UI framework and was using it to handle all my scripts. It was pretty cool being able to bookmark the scripts on the home screen and making appear to be a regular installed app. Anyway, here's the link to the wiki of the framework, it would be neat if someone took this and ported it for the ipad..the code is pretty damn simple so it shouldn't be much work....
KEEP YOUR SENSE OF HUMOR. Begin to bring job and happy moments into your life. Very few people suffer burnout when they're having fun.
Hehe, this is getting ridiculous...Wasn't friendfeed.com created before facebook? Even if it wasn't (or was) there is no way this could hold up.
@callmeed, Yes that is almost correct...they allow you to run FBJS on load.
@poundy, A mouseover will not work to run JS, I have tried.
I have been playing around with FBML,FBJS for the past few weeks...Say you wanted to load a external page(or for your case your recent image galleries) in a iframe, you will have to do something like this...
<a onClick="iframe_wrapper.setInnerFBML(the_iframe);" style="cursor: pointer;"> Click here to view your image gallery</a>
<div id="iframe_wrapper"> <fb:iframe width="560" height="560" src="hxxp://mywebsite.com></div>
<fb:js-string var="the_iframe"><fb:iframe width="560" height="560" src="hxxp://mywebsite.com></fb:js-string>
<script type="text/javascript" charset="utf-8"> var iframe_wrapper = document.getElementById('iframe_wrapper'); </script> -->
Really not a big deal for the users to have to click, but after reading thru there wiki I think using an iframe on a static fbml tab is frowned upon (I may be wrong?)..But anyway,I managed to do some pretty cool stuff with FBML+FBJS that I haven't seen done yet...If anyone wants to chat about this topic,leave your aim/skype/gtalk..=]
I remember jailbreaking my first iphone and installing a app, that did just that. The colors would fade in and out based on how loud you spoke. @andrewljohnson, If I were you I would make a short video of your app in action and post it up on youtube. I am sure that will get more people interested..
here we go, just had to dig thru the googles