<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Facebook JavaScript and Security</title>
	<atom:link href="http://ajaxian.com/archives/facebook-javascript-and-security/feed" rel="self" type="application/rss+xml" />
	<link>http://ajaxian.com/archives/facebook-javascript-and-security</link>
	<description>Cleaning up the web with Ajax</description>
	<lastBuildDate>Thu, 17 May 2012 07:43:39 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Ectara</title>
		<link>http://ajaxian.com/archives/facebook-javascript-and-security/comment-page-1#comment-276922</link>
		<dc:creator>Ectara</dc:creator>
		<pubDate>Wed, 02 Dec 2009 06:56:23 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=2648#comment-276922</guid>
		<description>I&#039;m 12 years old, and what is this?</description>
		<content:encoded><![CDATA[<p>I&#8217;m 12 years old, and what is this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: KirstenLeanneFaux</title>
		<link>http://ajaxian.com/archives/facebook-javascript-and-security/comment-page-1#comment-263053</link>
		<dc:creator>KirstenLeanneFaux</dc:creator>
		<pubDate>Wed, 23 Apr 2008 11:55:55 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=2648#comment-263053</guid>
		<description>I cannot use facebook properly, it keeps telling me to upgrade the javascript, how do i do this ?</description>
		<content:encoded><![CDATA[<p>I cannot use facebook properly, it keeps telling me to upgrade the javascript, how do i do this ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zaheer</title>
		<link>http://ajaxian.com/archives/facebook-javascript-and-security/comment-page-1#comment-253713</link>
		<dc:creator>zaheer</dc:creator>
		<pubDate>Thu, 09 Aug 2007 12:21:32 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=2648#comment-253713</guid>
		<description>I need some help. Can anyone tell me how can i use javascript with face book. i cannot even use alert(). Please explain as well.</description>
		<content:encoded><![CDATA[<p>I need some help. Can anyone tell me how can i use javascript with face book. i cannot even use alert(). Please explain as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: atshya</title>
		<link>http://ajaxian.com/archives/facebook-javascript-and-security/comment-page-1#comment-253701</link>
		<dc:creator>atshya</dc:creator>
		<pubDate>Thu, 09 Aug 2007 07:26:14 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=2648#comment-253701</guid>
		<description>Where can I get the demo?</description>
		<content:encoded><![CDATA[<p>Where can I get the demo?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrea Giammarchi</title>
		<link>http://ajaxian.com/archives/facebook-javascript-and-security/comment-page-1#comment-253686</link>
		<dc:creator>Andrea Giammarchi</dc:creator>
		<pubDate>Wed, 08 Aug 2007 22:29:31 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=2648#comment-253686</guid>
		<description>uhm ... above behaviour is correct only in a sandbox (but it works with FireFox, everytime)</description>
		<content:encoded><![CDATA[<p>uhm &#8230; above behaviour is correct only in a sandbox (but it works with FireFox, everytime)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrea Giammarchi</title>
		<link>http://ajaxian.com/archives/facebook-javascript-and-security/comment-page-1#comment-253685</link>
		<dc:creator>Andrea Giammarchi</dc:creator>
		<pubDate>Wed, 08 Aug 2007 22:20:59 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=2648#comment-253685</guid>
		<description>just posted in my blog ...

&lt;code&gt;delete Function;(this.Function&#124;&#124;parent.Function)(&quot;alert(&#039;safe?&#039;)&quot;)();&lt;/code&gt;</description>
		<content:encoded><![CDATA[<p>just posted in my blog &#8230;</p>
<p><code>delete Function;(this.Function||parent.Function)("alert('safe?')")();</code></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Schiller</title>
		<link>http://ajaxian.com/archives/facebook-javascript-and-security/comment-page-1#comment-253654</link>
		<dc:creator>Scott Schiller</dc:creator>
		<pubDate>Wed, 08 Aug 2007 17:18:52 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=2648#comment-253654</guid>
		<description>I imagine FB are going to have to step very, very carefully to prevent XSS-style holes in this service. Fortunately they have Joe Hewitt on their side. ;)</description>
		<content:encoded><![CDATA[<p>I imagine FB are going to have to step very, very carefully to prevent XSS-style holes in this service. Fortunately they have Joe Hewitt on their side. ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Neil Mix</title>
		<link>http://ajaxian.com/archives/facebook-javascript-and-security/comment-page-1#comment-253652</link>
		<dc:creator>Neil Mix</dc:creator>
		<pubDate>Wed, 08 Aug 2007 16:33:12 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=2648#comment-253652</guid>
		<description>Matjaz: Take a moment to read up on what FBJS is and how it works, the need for acrobatics will become clearer then.  FBJS rewrites the code so that all global accesses are prefix by an identifier unique to your application.  Any reference to the global &quot;Function&quot; get rewritten to something like &quot;asdf_Function&quot;.  So it&#039;s not as simple as what you propose, hence the &quot;long way&quot; (which has since been fixed by Facebook).</description>
		<content:encoded><![CDATA[<p>Matjaz: Take a moment to read up on what FBJS is and how it works, the need for acrobatics will become clearer then.  FBJS rewrites the code so that all global accesses are prefix by an identifier unique to your application.  Any reference to the global &#8220;Function&#8221; get rewritten to something like &#8220;asdf_Function&#8221;.  So it&#8217;s not as simple as what you propose, hence the &#8220;long way&#8221; (which has since been fixed by Facebook).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MatjaÅ¾</title>
		<link>http://ajaxian.com/archives/facebook-javascript-and-security/comment-page-1#comment-253651</link>
		<dc:creator>MatjaÅ¾</dc:creator>
		<pubDate>Wed, 08 Aug 2007 15:51:47 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=2648#comment-253651</guid>
		<description>what about:
=============
var exploit = new Function(&quot;alert(&#039;arbitrary code&#039;)&quot;);
exploit ();
=============
that&#039;s what Neil did, but in a long way. :/</description>
		<content:encoded><![CDATA[<p>what about:<br />
=============<br />
var exploit = new Function(&#8220;alert(&#8216;arbitrary code&#8217;)&#8221;);<br />
exploit ();<br />
=============<br />
that&#8217;s what Neil did, but in a long way. :/</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian</title>
		<link>http://ajaxian.com/archives/facebook-javascript-and-security/comment-page-1#comment-253637</link>
		<dc:creator>Adrian</dc:creator>
		<pubDate>Wed, 08 Aug 2007 12:18:28 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=2648#comment-253637</guid>
		<description>That means the black hat hackers where afraid of CIA if they didn&#039;t tryed anything fishy on FB?</description>
		<content:encoded><![CDATA[<p>That means the black hat hackers where afraid of CIA if they didn&#8217;t tryed anything fishy on FB?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

