[orkut-developer] Re: Apps XSS loopholes!

2008-12-18 Thread Vijaya
Hi Prashanth, I just realized that this feature was released to a very small percentage of the orkut users, which includes our team. That's the reason I was seeing the link and you were not. I'm very sorry for misleading you, but this feature is just around the corner and you can use the same for

[orkut-developer] Re: Apps XSS loopholes!

2008-12-17 Thread Prashant PatilĀ­
Sorry to say but there is so such option in my profile :( Take care of this app too http://www.orkut.com/Application.aspx?uid=7860528114958215308&appId=567868578162 Its fake page with some login error If you are thinking not to post any apps XSS related things in this group let me know. But i

[orkut-developer] Re: Apps XSS loopholes!

2008-12-16 Thread Vijaya
In the profile view of the apps, at the bottom of each app, you should see the following link: http://graargh.returnstrue.com/maverick/pix/reportApps.png --~--~-~--~~~---~--~~ You received this message because you are subscribed to the Google Groups "Orkut Develope

[orkut-developer] Re: Apps XSS loopholes!

2008-12-16 Thread Prashant PatilĀ­
HI V, There is no such option to report apps in Profile View , Canvas View even Apps info view. It was there but now missing. Correct me if i am wrong with the exact location. On Tue, Dec 16, 2008 at 12:36 PM, Vijaya wrote: > > Just to followup, we have taken down the apps and notified the >

[orkut-developer] Re: Apps XSS loopholes!

2008-12-15 Thread Vijaya
Just to followup, we have taken down the apps and notified the developers of the apps about the potentials for exploitation. Thank you. Vijaya --~--~-~--~~~---~--~~ You received this message because you are subscribed to the Google Groups "Orkut Developer Forum" g

[orkut-developer] Re: Apps XSS loopholes!

2008-12-15 Thread Vijaya
Hi Prashant, Thank you for reporting these apps to us. We'll look into them. In the future, can you please use the 'report app' link at the bottom of the app so we can escalate the issue appropriately? Thanks again, Vijaya --~--~-~--~~~---~--~~ You received this me