Pownce pwned

July 26th, 2007 | by tk2 |

Ah finally, pownce sent me an invitation mail. Well, the content is too simple. No images, just plain text with a link.

You’re invited to Pownce!

You can signup by using this link:
http://pownce.com/signup/W4IRT/

Or by visiting Pownce and entering the following information during
sign up.

Invitation code: W4IRT
Email: tk2@yahoo.com

Pownce is a new way to send messages, files, events, pictures, and
links to your friends.

Welcome!

The Pownce Crew

You might be wondering why I chose to wait for the invitation mail instead of requesting it from other users. Well, I guess some else deserve it better than me. I’m not going to write any review since every single blogger in blogsphere has posted about it before.

The nice thing is, I found a XSS vulnerability 6 minutes after my first login. So why not share it to public?

XSS pownce

6 fresh invitations to give. Anyone?
BTW, I’m home.~

EDIT:

After googling around I found out that someone already discovered the same bug in invite friend page last 11 days and posted it to digg.

  1. One Response to “Pownce pwned”

  2. By Hertz on Aug 9, 2007 | Reply

    Hey, I’m wondering if you’re still any Pownce invitations left. I’d love to get a Pownce :) Thank you.

Post a Comment