pronetadvertising.com — Digg's new friend referral feature has had some unintended consequences... By adding a snippet of code, people can automatically force-add themselves as your friend without your permission and without you even knowing!
Apr 2, 2007 View in Crawl 4
theattacksApr 2, 2007
this is still in the queue, digg's crew must be at lunch
grendelboogieApr 2, 2007
This was fixed early last Friday morning. Nothing to see, move along.
grendelboogieApr 2, 2007
Skitzzo,I did.Here's the link to the original blog that demoed the issue:<a class="user" href="http://www.thegooglecache.com/rants-and-raves/new-digg-feature-friend-spamming-proof-of-concept/">http://www.thegooglecache.com/rants-and-raves/new-digg-feature-friend-spamming-proof-of-concept/</a>which msaleem also links to. If you read to the end of the comments, you can see that there are reports it doesn't work anymore.Also, here at digg, we have verified that this particular exploit doesn't work anymore. Onto looking for the next one...
skitzzoApr 2, 2007Submitter
grendel, if you've read the post then you should realize that the author states it still worked for him as of 2 am this morning. How do you explain that?Maybe before you move onto "the next one" you should investigate this one a bit more?
grendelboogieApr 2, 2007
@Skitzzo,Try it and let us know if there are still problems. If you are automatically added, we'll investigate further.
skitzzoApr 2, 2007Submitter
@grendel, fair enough. I'll give it a go and let you know. (I'm a poet and didn't know it - shoot me know please)P.S. Did this story get removed from the upcoming queue?
wackosApr 5, 2007
Hey, grendelboogie, we tested it out and sure enough, it was only half way fixed!!! You guys were still screwed up. NOW it's fixed.