<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Praetorian Prefect &#187; Social Networking</title>
	<atom:link href="http://praetorianprefect.com/archives/category/social-networking/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Thu, 19 Jan 2012 03:59:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Persistent XSS on Twitter.com</title>
		<link>http://praetorianprefect.com/archives/2010/06/persistent-xss-on-twitter-com/</link>
		<comments>http://praetorianprefect.com/archives/2010/06/persistent-xss-on-twitter-com/#comments</comments>
		<pubDate>Thu, 24 Jun 2010 08:32:11 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[post-wide]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=4423</guid>
		<description><![CDATA[Twitter user 0wn3d_5ys has demonstrated a persistent cross site scripting (XSS) vulnerability he found on  June 21st using his own Twitter account (visit at your own risk) that appears to be due to a lack of input validation of the application name field when accepting new requests for Twitter applications.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/06/persistent-xss-on-twitter-com/feed/</wfw:commentRss>
		<slash:comments>15</slash:comments>
		</item>
		<item>
		<title>James Lipton says &#8220;Don&#8217;t tweet your junk&#8221;</title>
		<link>http://praetorianprefect.com/archives/2009/12/james-lipton-says-dont-tweet-your-junk/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/james-lipton-says-dont-tweet-your-junk/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 23:46:57 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Stay Safe Online]]></category>
		<category><![CDATA[Technology in Society]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[staying safe online]]></category>
		<category><![CDATA[teenagers]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1937</guid>
		<description><![CDATA[James Lipton's new public service announcements (PSA's) on texting (text messaging) for teenagers gives the concept a whole new meaning. The campaign "Before you test, give it a ponder" features videos of Lipton loaning his trademark beard to teenagers so that its magical properties of forethought can be temporarily bestowed on them effectively uses humor to combat the problems of <a href="http://en.wikipedia.org/wiki/Sexting">sexting</a> and <a href="http://en.wikipedia.org/wiki/Cyberbullying">cyber-bullying</a>.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/james-lipton-says-dont-tweet-your-junk/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>“Hi. This you?? LOL” Twitter Attack Snares Kevin Mitnick</title>
		<link>http://praetorianprefect.com/archives/2009/11/%e2%80%9chi-this-you-lol%e2%80%9d-twitter-attack-snares-kevin-mitnick/</link>
		<comments>http://praetorianprefect.com/archives/2009/11/%e2%80%9chi-this-you-lol%e2%80%9d-twitter-attack-snares-kevin-mitnick/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 16:16:33 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[brute force]]></category>
		<category><![CDATA[mitnick]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1811</guid>
		<description><![CDATA[Historically the “Is this you?” style Twitter attack seems to be seeded by either an original break in to the victim’s Twitter account, or that user having provided his or her credentials to a phishing style web site made to look like Twitter as the attack propagates through the popular micro-blogging service. This time around however, the <a href="http://www.twitter.com/KevinMitnick">account</a> of security consultant and former cracker Kevin Mitnick was caught up in this generic, untargeted Twitter “worm”.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/11/%e2%80%9chi-this-you-lol%e2%80%9d-twitter-attack-snares-kevin-mitnick/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Not the Haus of Gaga too</title>
		<link>http://praetorianprefect.com/archives/2009/11/not-the-haus-of-gaga-too/</link>
		<comments>http://praetorianprefect.com/archives/2009/11/not-the-haus-of-gaga-too/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 08:20:58 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[brute forcing]]></category>
		<category><![CDATA[defacement]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1723</guid>
		<description><![CDATA[Around 9pm EST on Monday the Twitter account of pop singer Lady Gaga, <a href="http://www.twitter.com/ladygaga">@ladygaga</a> was cracked in to and a series of messages added to her tweet stream. This is the second high profile Twitter account to be cracked in the last few days, on Friday the account of pop singer Britney Spears, @BritneySpears, started professing sympathy for the devil. The Lady Gaga one is interesting though, because like an homage to old school cracks of the past, the attackers appear to have left their name. Further these are two high profile accounts broken into after Twitter has implemented at least three major changes to their web site's authentication process.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/11/not-the-haus-of-gaga-too/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Facebook’s Faith: A New Scareware Attack</title>
		<link>http://praetorianprefect.com/archives/2009/10/facebook%e2%80%99s-faith-a-new-scareware-attack/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/facebook%e2%80%99s-faith-a-new-scareware-attack/#comments</comments>
		<pubDate>Thu, 01 Oct 2009 21:22:43 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[capthca]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[non-technical]]></category>
		<category><![CDATA[Scareware]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=684</guid>
		<description><![CDATA[On Thursday morning, AVG researcher Roger Thompson, after sourcing some spyware attacks to a series of Facebook profiles, noted that these few hundred profiles were showing up with the same profile image (seen at left) but different profile information.  The home video link on these profiles, belonging to Faith / Emily / whoever, points to the a web site that displays scareware dialogs.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/facebook%e2%80%99s-faith-a-new-scareware-attack/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Breaking Twitter (authentication)</title>
		<link>http://praetorianprefect.com/archives/2009/09/breaking-twitter-authentication/</link>
		<comments>http://praetorianprefect.com/archives/2009/09/breaking-twitter-authentication/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 17:26:54 +0000</pubDate>
		<dc:creator>Jeremy Rossi</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[tweethon]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=530</guid>
		<description><![CDATA[But wait you say, are you trying to tell us that brute force password attacks will move to the API when I just read on the Twitter API wiki that the API severely limits the rate of calls you are allowed to make to it (200/hour/IP for authenticated requests without whitelisting)?  That should be a mitigating control.  Should be, but isn't, because it is not enforced on all of the API calls.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/09/breaking-twitter-authentication/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>ROFL this you on here? The latest Twitter Worm</title>
		<link>http://praetorianprefect.com/archives/2009/09/rofl-this-you-on-here-the-latest-twitter-worm/</link>
		<comments>http://praetorianprefect.com/archives/2009/09/rofl-this-you-on-here-the-latest-twitter-worm/#comments</comments>
		<pubDate>Thu, 24 Sep 2009 08:25:29 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[captcha]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[money mule]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=484</guid>
		<description><![CDATA[At 2pm on Wednesday 9/24, wide scale reports started showing up on Twitter that a new Twitter worm sends you a direct message with the content “rofl this you on here? http://videos.twitter.secure-logins01.com”.  The link opens a Twitter style log in page (albeit Twitter’s previous version of this page, they have a new one) which, except for being an old version and a stray angle bracket is convincing.  Upon logging in the user’s credentials are stolen, and presumably direct messages are sent to each follower that user has.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/09/rofl-this-you-on-here-the-latest-twitter-worm/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>CollegeHumor explores the concept of real life tweeting</title>
		<link>http://praetorianprefect.com/archives/2009/05/collegehumor-explores-the-concept-of-real-life-tweeting/</link>
		<comments>http://praetorianprefect.com/archives/2009/05/collegehumor-explores-the-concept-of-real-life-tweeting/#comments</comments>
		<pubDate>Fri, 01 May 2009 23:33:26 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Networking]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=181</guid>
		<description><![CDATA[What if you walked through life providing twarcissistic updates as some are wont to do on Twitter. CollegeHumor.com explores what this might look like.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/05/collegehumor-explores-the-concept-of-real-life-tweeting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

