kefka or whoever: theres a proxy XSS in adidas.com that i'm sure won't be blocked then .. http://www.adidas.com/scripts/cud/cud.asp?call=registeremail&Postprocessor=http://tinyurl.com/2tx&dateofbirth_dd=1&dateofbirth_mm=1&dateofbirth_yyyy=1 but sadly, it pulls each page with a post so its a bit cumbersome. Instead just register for a free webhost somewhere and add a page that includes this script:
<script>
if (location.search.slice(1)) document.write('<iframe height="100%" width="100%" src="'+location.search.slice(1)+'"></iframe>');
</script>
Use: http://yoursite.com/proxy.html?http://google.com
adio: use the link whiteacid posted, worked great for me on myspace .. and you can add quicktime movies to your profile.. i'll put it back up on mine in a bit, to demonstrate.
-maluc