I can't believe it 
It's 3 AM and I'm laughing out loud, I just can't believe it! Once again I find myself amused with the efforts (or lack of them) of hi5.com developing team.
Well, I didn't report the last javascript injection, it was an injection within a link and we couldn't change the document object. Just a few minutes ago I remembered to re-check if by any divine act they would have fixed that, and they didn't… But that's not the problem, I just tried my old XSS attack and it worked again, it seems they have reversed the patch. Oh god.. Tomorrow if I remember I'll be reporting
again this problem.
Until then, my
profile is once again redirecting to my hi5
spoofed login page.
If you are interested in having some fun you can always add the following line to any of the fields that support html, like the "about me" field:
<img src="" onError="window.document.images[2].src='http://pabrantes.dyndns.org/gozo.jpg';">
This code will switch the hi5 image logo in your profile main page for another one up side down.