Post Page Advertisement [Top]


Performing a Google Search For "inurl:bcode=[*]+n_m=[*] site:facebook.com" dork can link to the accounts of 1.3 million facebook accounts would showup, some of the accounts can be utilized to gain access to the user profile without any password.

nico-roddz member of Hacker News, identified this issue and claims that he noticed the bug when his friend sent him a link, his friend forward this email from facebook group, Email: (http://www.facebook.com/n/?group%{id here]/permalink %[id here]/&mid=[id here]&bcode= [id here]-mjoi&n_m[Email Address]). 
when clicking that url its automatically logged into my friend profile without any authentication.

'Facebook Security Team' noticed the Hacker News thread and patch that security hole.



Bottom Ad [Post Page]

| Coded by Gekza Technologies