<?xml version="1.0"?><!-- generator="bbPress" -->

<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
>

<channel>
<title>Xanga Help Topic: John: you have a critical integrity/security issue, nfp.</title>
<link>http://help.xanga.com/</link>
<description>Xanga Help Topic: John: you have a critical integrity/security issue, nfp.</description>
<language>en</language>
<pubDate>Sat, 09 May 2026 03:30:23 +0000</pubDate>

<item>
<title>StupidSystemus on "John: you have a critical integrity/security issue, nfp."</title>
<link>http://help.xanga.com/topic/john-you-have-a-critical-integrity-issue-nfp?post_id=1610#post-1610</link>
<pubDate>Sun, 08 Sep 2013 15:24:42 +0000</pubDate>
<dc:creator>StupidSystemus</dc:creator>
<guid isPermaLink="false">1610@http://help.xanga.com/</guid>
<description>&#60;p&#62;I caught that, too. It seems like this Super Admin functionality was inherited through all Xanga users. The good thing is you can only edit comments made on your posts.&#60;/p&#62;
&#60;p&#62;Technically, this is not an issue. From a site owner's perspective, I should be able to edit and/or redact comments from people under my discretion. I can see that being abused, however.
&#60;/p&#62;</description>
</item>
<item>
<title>notforprophet on "John: you have a critical integrity/security issue, nfp."</title>
<link>http://help.xanga.com/topic/john-you-have-a-critical-integrity-issue-nfp?post_id=1600#post-1600</link>
<pubDate>Sun, 08 Sep 2013 10:56:30 +0000</pubDate>
<dc:creator>notforprophet</dc:creator>
<guid isPermaLink="false">1600@http://help.xanga.com/</guid>
<description>&#60;p&#62;There is a critical information security integrity issue with 2.0's commenting implementation: Comment editing for the comment receiver is turned on.&#60;/p&#62;
&#60;p&#62;There is probably a very easy sitewide on-off switch solution on your admin console side for this.&#60;/p&#62;
&#60;p&#62;Proof of concept here: &#60;a href=&#34;http://notforprophet.xanga.com/2013/09/08/7974/#comments&#34; rel=&#34;nofollow&#34;&#62;http://notforprophet.xanga.com/2013/09/08/7974/#comments&#60;/a&#62;&#60;/p&#62;
&#60;p&#62; - nfp
&#60;/p&#62;</description>
</item>

</channel>
</rss>
