<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>A Weird Soul - Latest Comments in Brijj.com bug</title><link>http://gsharma.disqus.com/</link><description></description><language>en</language><lastBuildDate>Thu, 07 Aug 2008 21:02:15 -0000</lastBuildDate><item><title>Re: Brijj.com bug</title><link>http://www.gsharma.com/brijjcom-bug/#comment-1129405</link><description>Yes, it was for Kapil.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">gsharma</dc:creator><pubDate>Thu, 07 Aug 2008 21:02:15 -0000</pubDate></item><item><title>Re: Brijj.com bug</title><link>http://www.gsharma.com/brijjcom-bug/#comment-1129353</link><description>Tech Architect? You're referring to Kapil, rite? :)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Gaurav Sharma</dc:creator><pubDate>Thu, 07 Aug 2008 20:56:33 -0000</pubDate></item><item><title>Re: Brijj.com bug</title><link>http://www.gsharma.com/brijjcom-bug/#comment-1128693</link><description>I just found out that you were Technical Architect on &lt;a href="http://Brijj.com" rel="nofollow"&gt;Brijj.com&lt;/a&gt; and it uses Symfony. I haven't dug deep into Symfony, but I'd imagine their basic auth module/plugin will hash passwords before saving them.&lt;br&gt;&lt;br&gt;I wonder if &lt;a href="http://Brijj.com" rel="nofollow"&gt;Brijj.com&lt;/a&gt; isn't fully using Symfony to its potential?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">gsharma</dc:creator><pubDate>Thu, 07 Aug 2008 19:37:44 -0000</pubDate></item><item><title>Re: Brijj.com bug</title><link>http://www.gsharma.com/brijjcom-bug/#comment-1128557</link><description>Kapil, this has nothing to do with LinkedIn API or even LinkedIn. I guess I chose a bad example for the iframe.&lt;br&gt;&lt;br&gt;See the URL in the screenshot - &lt;a href="http://www.flickr.com/photos/gsharma/2740079054/sizes/o/" rel="nofollow"&gt;http://www.flickr.com/photos/gsharma/2740079054...&lt;/a&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">gsharma</dc:creator><pubDate>Thu, 07 Aug 2008 19:23:50 -0000</pubDate></item><item><title>Re: Brijj.com bug</title><link>http://www.gsharma.com/brijjcom-bug/#comment-1121240</link><description>Interesting find. looks like some authentication issue with the Linkedin API</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Kapil</dc:creator><pubDate>Thu, 07 Aug 2008 07:25:39 -0000</pubDate></item><item><title>Re: Brijj.com bug</title><link>http://www.gsharma.com/brijjcom-bug/#comment-1118365</link><description>It all boils down to the Tech Lead / Programmers. They certainly don't seem to have any coding standards. 'Lack of experience' I assume. Moreover, quantity is rated higher than quality (in India). Pity. &lt;br&gt;I suggest you change your passwords NOW ;-)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Gaurav Sharma</dc:creator><pubDate>Wed, 06 Aug 2008 21:31:53 -0000</pubDate></item><item><title>Re: Brijj.com bug</title><link>http://www.gsharma.com/brijjcom-bug/#comment-1118242</link><description>I apparently did that. &lt;br&gt;&lt;br&gt;They don't encrypt your password either. I did the 'forgot my password' thing and they emailed me my existing password in plain text. Yikes! Info Edge, a publicly traded company, needs to improve their coding quality.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">gsharma</dc:creator><pubDate>Wed, 06 Aug 2008 21:12:41 -0000</pubDate></item><item><title>Re: Brijj.com bug</title><link>http://www.gsharma.com/brijjcom-bug/#comment-1118196</link><description>i wudn't be trusting this site with my email credentials ( &lt;a href="http://brijj.com/aboutus/TakeATourPage2" rel="nofollow"&gt;http://brijj.com/aboutus/TakeATourPage2&lt;/a&gt; ). A 1 year old indian website.. hmmm :-s</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Gaurav Sharma</dc:creator><pubDate>Wed, 06 Aug 2008 21:06:28 -0000</pubDate></item><item><title>Re: Brijj.com bug</title><link>http://www.gsharma.com/brijjcom-bug/#comment-1117898</link><description>No, just a XSS vulnerability on Brijj. Click the image to see the URL.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">gsharma</dc:creator><pubDate>Wed, 06 Aug 2008 20:26:05 -0000</pubDate></item><item><title>Re: Brijj.com bug</title><link>http://www.gsharma.com/brijjcom-bug/#comment-1117864</link><description>LinkedIn API?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Gaurav Sharma</dc:creator><pubDate>Wed, 06 Aug 2008 20:21:29 -0000</pubDate></item></channel></rss>