• Home
  • Advertise
  • Contact Us
  • Free eBooks
  • Infographics
  • About Us


  • Technology
    • Programming
      • Java
      • PHP
      • HTML
      • CSS
      • Javascript
      • XML
      • AJAX
      • JQuery
      • Perl
      • IDE
    • CMS
      • Opencart
      • WordPress
      • Prestashop
      • Magento
    • Database
  • Security
    • Cyber Laws
    • Digital Signature
    • Passwords
    • Reverse Engineering
    • Steganography
    • Forensics
    • Networking
  • E-Commerce
  • Digital Media
    • SEO
    • Social Media
      • Facebook
  • Gadgets
    • Laptops
    • Tablets
    • Just CellPhones
    • Social CellPhones
  • OS
    • Linux
    • Mac
    • Windows
    • iOS
    • Android
  • Courses
    • Development in Android
  • General

Breaking

The supercomputer "Tianhe-2" Takes No. 1 Ranking on 41st TOP500 List

Export tweets in different formats

OWASP - Top 10 Vulnerabilities

New Windows-backdoor deletes MBR

The world's first CPU of 5GHz

Critical vulnerability in 60 + models of CCTV and IP-cameras

Hack a Samsung TV with SmartTV function

The man who "almost broke the Internet"

The search continues for the sixth member of LulzSec

Statistics on the botnet Carna


Facebook Pwn collects information about user profiles

0 Comment
 15 Sep 2011   Posted by synt4x

1 Star2 Stars3 Stars4 Stars5 Stars
Loading ... Loading ...


flattr this!

Tools, tricks users Facebook, uses a request to add them to friends in order to obtain personal data that can later be used for online fraud.

The Group of Experts on Information Security, based in Egypt, has created a tool that facilitates social engineering. It automates the collection of sensitive data in user profiles, Facebook, which can only be accessed by friends in a social network.

Cross-platform Java-tool called “Facebook Pwn” and described the creators as “the dumper for the profiles of Facebook”.

“(Tool) sends requests to add to friends list users Facebook, and then calculates the positive notice of acceptance of friends. As soon as the victim accepts the invitation, all its data immediately merge – photos and friends list” – says in the description of the program.

In a typical scenario described by the researchers, the hacker begins collecting information from the user profile by creating a new, empty profile. Then uses the so-called “friending plugin”, with which you can add to my friends, all friends of his victim. This ensures that you are the victim of mutual friends, the researchers note. Further cloning plug-in asks you to select one of the friends of the victim. Then it clones only the picture and name of the selected friend to your account.

After that, a request to add to friends send the victim to a fake account of its “friend.” The tool is waiting for a positive response from the victim, explained in the description of the program. As soon as the victim accepts the invitation, the dumper immediately begins to gather all available information from the pages of (information, pictures, links, etc.) for further study offline.

“Maybe in a few minutes the victim will remove fake profiles from your friends list, after he / she realizes that he not real, but most likely it will be too late!” – The researchers explain.

In a group of developers tools, posted on the site Google code, said that it was developed only in the “proof of concept” and should be used at your own risk, and not to “abuse”. And their request, no doubt, will be heard all the hackers who have no intentions too.

Spread The Word:

  • Facebook
  • Twitter
  • Pinterest
  • StumbleUpon
  • Google +1
  • Digg
  • Reddit
  • Email
  • LinkedIn
  • Tumblr
    Share This


Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

  • Find Us On Facebook

  • Airtel Hello Tunes

  • Ads.

  • Ads.

  • Shrugs Online


  • More...

    • Advertise
    • Crawl Fashion | Fashion Directory
    • Information Technology Act 2000 Compliance [Sec 43A and Sec 72A]
    • Java Tutorial
    • Netbeans Tutorial
    • Photography Blogs
    • Street Shopping
    • Virus Protection And Internet Security
  • Recent Posts

    • OWASP - Top 10 Vulnerabilities
    • New Windows-backdoor deletes MBR
    • Critical vulnerability in 60 + models of CCTV and IP-cameras
    • Hack a Samsung TV with SmartTV function
    • The man who "almost broke the Internet"
    • The search continues for the sixth member of LulzSec
  • Enter your email address to subscribe to "Bytes" Mag & receive THE latest updates on Tech!


Copyright © LetsByteCode Inc.
DMCA.com
loading Cancel
Post was not sent - check your email addresses!
Email check failed, please try again
Sorry, your blog cannot share posts by email.