<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Inius Trivia &#187; social media</title>
	<atom:link href="http://www.inius.ro/tags/social-media/feed" rel="self" type="application/rss+xml" />
	<link>http://www.inius.ro</link>
	<description>Nothing special. Everything.</description>
	<lastBuildDate>Wed, 26 Oct 2011 17:45:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>EAVB_HAJLUXHDCE</title>
		<link>http://www.inius.ro/posts/142-eavb_hajluxhdce.html</link>
		<comments>http://www.inius.ro/posts/142-eavb_hajluxhdce.html#comments</comments>
		<pubDate>Sat, 14 Aug 2010 17:39:43 +0000</pubDate>
		<dc:creator>Lucian</dc:creator>
				<category><![CDATA[Web]]></category>
		<category><![CDATA[games]]></category>
		<category><![CDATA[social media]]></category>

		<guid isPermaLink="false">http://www.inius.ro/?p=142</guid>
		<description><![CDATA[Wondering what this means? Well, it&#8217;s a verification code from an online social game that seems so interesting that I will share it with you: www.empireavenue.com. It reminds me from Dreamshares.com, but Dreamshares was (&#8220;was&#8221;, because now is dead) about sports, while Empire Avenue it&#8217;s about social networking. You must buy and sell stocks in [...]]]></description>
			<content:encoded><![CDATA[<p>Wondering what this means? Well, it&#8217;s a verification code from an online social game that seems so interesting that I will share it with you: <a rel="nofollow" href="http://www.empireavenue.com" target="_blank">www.empireavenue.com</a>.</p>
<p>It reminds me from <a href="http://www.dreamshares.com" target="_blank">Dreamshares.com</a>, but Dreamshares was (&#8220;was&#8221;, because now is dead) about sports, while Empire Avenue it&#8217;s about social networking. You must buy and sell stocks in persons and become an influential person.</p>
<p>EAVB_HAJLUXHDCE</p>
]]></content:encoded>
			<wfw:commentRss>http://www.inius.ro/posts/142-eavb_hajluxhdce.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Invitation to phishing: Facebook Connect</title>
		<link>http://www.inius.ro/posts/98-invitation-to-phishing-facebook-connect.html</link>
		<comments>http://www.inius.ro/posts/98-invitation-to-phishing-facebook-connect.html#comments</comments>
		<pubDate>Tue, 20 Jul 2010 19:22:55 +0000</pubDate>
		<dc:creator>Lucian</dc:creator>
				<category><![CDATA[CSS3 Fantasy]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[social media]]></category>

		<guid isPermaLink="false">http://www.inius.ro/?p=98</guid>
		<description><![CDATA[I worked these days on a &#8220;Facebook Connect&#8221; implementation. While working on it, I suddenly had a revelation: this Facebook Connect it&#8217;s an invitation to phishing! Let&#8217;s take a look at Digg.com, a website that uses Facebook connect. When you click on the button: &#8220;Connect with Facebook&#8221;, a pop-up window like in the screen below [...]]]></description>
			<content:encoded><![CDATA[<p>I worked these days on a &#8220;Facebook Connect&#8221; implementation. While working on it, I suddenly had a revelation: this Facebook Connect it&#8217;s an invitation to phishing!</p>
<p>Let&#8217;s take a look at Digg.com, a website that uses Facebook connect. When you click on the button: &#8220;Connect with Facebook&#8221;, a pop-up window like in the screen below will appear:</p>
<p><a href="http://www.inius.ro/wp-content/uploads/2010/07/fbkc.jpg" target="_blank"><img class="aligncenter size-medium wp-image-99" title="Facebook Connect phishing" src="http://www.inius.ro/wp-content/uploads/2010/07/fbkc-300x187.jpg" alt="" width="300" height="187" /></a></p>
<p>Problem is, that even a script kiddie can very easily emulate this pop-up window. It took me only 1/2 hours to get this button to work (click on it, works only on CSS3 browsers):</p>
<div style="margin: 10px;"><span style="background: #003366; color: white; font-family: 'Lucida Grande'; padding: 5px;"><strong>f</strong> | <span style="font-size: 11px;"><a style="color: white; text-decoration: none;" href="http://www.inius.ro/samples/fbk-phishing.html" target="_blank">Connect with Facebook</a></span></span></div>
<p>I&#8217;m wondering, how many time would need somebody really interested in phishing accounts to setup a perfect clone and start asking for &#8220;Facebook connections&#8221;? 2 hours? 3 hours?</p>
<p>People think that this is not so bad, as long as the phisher&#8217;s website has nothing to offer, but a smart phisher will be persuasive enough in order to make the people think that they should provide their login credentials. For example the phisher could pretend that he gives on his website the next lottery&#8217;s winning numbers.</p>
<p>Very, very bad for Facebook. Facebook really, really sucks with this.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.inius.ro/posts/98-invitation-to-phishing-facebook-connect.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

