Main » 2011 » September » 2 » FBML Injection on Facebook Stream Attachments
9:54 AM
FBML Injection on Facebook Stream Attachments
FBML InjectionAs you might already know, on Facebook, we can insert some certain media attachment like image, video/flash or mp3 audio through our own application. The attachment is an array of structured data that defines the post. To understand how to post what kind of attachment we would like to post, we need to understand about Facebook Stream Attachments. You can read more about the detail on their page. Here, we are discussing the issue on one of its parameters named "name”.

You can use this Stream Attachments through :

As i said above before, here we’re gonna try to use the ‘name’ parameter on the attachment to add an FBML Injection to our post. This trick found by some of our brothers and sisters on balikita, inspired by a tag button then Roy Castillo use fb:lives-tream, then tweaked more by some other forum members. Let’s assume that you have already known about how to insert the attachment, you can insert some FBML codes inside the parameter like :

You can try to insert those FBML tag using our Facebook Bold Text, simply put those FBML codes inside the ‘Message’ Box, there’s also a preview button. You can find more about FBML tag on this page : http://developers.facebook.com/docs/reference/fbml/ try it, who knows you will find another way to insert XSS vector using this trick :)


FBML Injection on Facebook Stream Attachments
I’m using the trick to show visitor profile picture on newsfeed, try it yourself on your wall by clicking this link :
http://apps.facebook.com/bold-text/?blessedfriend

Happy tweaking ;)


Category: Facebook Hacks | Views: 2794 | Added by: 3x3r00t | Rating: 0.0/0
Total comments: 0
Only registered users can add comments.
[ Registration | Login ]
Recommend on Google

Designed By [#]./3X3.R()()T
Like Us on Facebook Follow Us on Twitter Subscribe Us on Youtube WWW.GeniusHackers.NET © 2024
Founder and CEO of GeniusHackers [#] /3x3.R()()T
Hosted by uCoz