She-geeks Forum
May 22, 2012, 12:49:45 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: Get the Hacker's Underground Handbook:
http://www.she-geeks.com/hackers-underground-handbook1.html
 
   Home   Help Search Login Register  
Pages: 1 2 3 4 5 »   Go Down
  Print  
Author Topic: photostalker and photos privacy  (Read 6901 times)
0 Members and 1 Guest are viewing this topic.
CornellWeasel
Honored Member
Full Member
********

Karma: 341
Offline Offline

Posts: 232



« on: May 21, 2009, 05:37:00 PM »

So, I have my real FB's photos privacy set to "everyone" (under Settings > Applications Settings), and most individual albums (under Privacy > Photos) set to "friends only," with 2 albums sent to "everyone." (Previously, I had all albums set to friends only, but changed the settings to "everyone" for the 2 albums so that I could test the accuracy of photostalker).

Thing is that, even though my general settings for the photos are public, photostalker still cannot access the public albums. Any idea why?

I don't exactly need to make those photos public, as my profile is private anyway. I'm just curious as to why that app can't access two albums that are public.
Logged
Angry Johnny
Global Moderator
Sr. Member
****************

Karma: 3849
Offline Offline

Posts: 614



« Reply #1 on: May 23, 2009, 11:59:02 AM »

So, I have my real FB's photos privacy set to "everyone" (under Settings > Applications Settings), and most individual albums (under Privacy > Photos) set to "friends only," with 2 albums sent to "everyone." (Previously, I had all albums set to friends only, but changed the settings to "everyone" for the 2 albums so that I could test the accuracy of photostalker).

Thing is that, even though my general settings for the photos are public, photostalker still cannot access the public albums. Any idea why?

I don't exactly need to make those photos public, as my profile is private anyway. I'm just curious as to why that app can't access two albums that are public.

I think it has to do with the last part: your profile is private.  It can catch it on 'non' private facebooks, but not private.  At least, that's what I thought I read.  Been a month or so since I used the app, though.
Logged

Don't take life too seriously.  You'll never get out of it alive.
CornellWeasel
Honored Member
Full Member
********

Karma: 341
Offline Offline

Posts: 232



« Reply #2 on: May 24, 2009, 05:59:53 PM »

One of my targets just went private not too long ago, but I can access his/her photos through the app. That's the reason I wanted to understand why my profile is not accessing my public photos as well.


Logged
Angry Johnny
Global Moderator
Sr. Member
****************

Karma: 3849
Offline Offline

Posts: 614



« Reply #3 on: May 25, 2009, 07:26:41 AM »

don't know what to say, then.  I could conjecture, but, I didn't make the app, so anything I may say could be wrong.  Could also, very well, be it won't work on 'you' specifically, as in, if you try to view yourself through your actual profile, it may not work...curious, how private are we talking here, anyways?  I keep mine private to an extent, but reopened it as I have nothing too problematic on there.
Logged

Don't take life too seriously.  You'll never get out of it alive.
roxyb
Jr. Member
***

Karma: 49
Offline Offline

Posts: 72



« Reply #4 on: May 30, 2009, 05:15:15 PM »

I found a fusker program the other day called navnet [navnetapp (dot) com.]  It supposedly can fusker photobucket and facebook for photos.  Has anyone used it?
Logged
Jewels
Administrator
Hero Member
**************

Karma: 5056
Offline Offline

Posts: 1633


gettin my geek on!


WWW
« Reply #5 on: May 30, 2009, 06:23:33 PM »

There are several posts around the forum for fuskering with navnet
Logged

Need any creative work done? I recommend Bryan Langdeau. This man's work has been blowing me away since he was 10 years old...
roxyb
Jr. Member
***

Karma: 49
Offline Offline

Posts: 72



« Reply #6 on: May 30, 2009, 07:55:10 PM »

Thanks.  I'll go look.
Logged
CornellWeasel
Honored Member
Full Member
********

Karma: 341
Offline Offline

Posts: 232



« Reply #7 on: June 02, 2009, 04:13:04 PM »

don't know what to say, then.  I could conjecture, but, I didn't make the app, so anything I may say could be wrong.  Could also, very well, be it won't work on 'you' specifically, as in, if you try to view yourself through your actual profile, it may not work...curious, how private are we talking here, anyways?  I keep mine private to an extent, but reopened it as I have nothing too problematic on there.

I was checking my own picts through a fake profile (so, I'd login to fake, then look up my real profile to get the friend ID, and then input that ID to the app).

My profile can be viewed by friends only; my list of friends can also be viewed by friends only. I tried changing my list of friends to be viewed by everyone (in case that privacy setting was the one affecting how the app works), but that didn't work either. I keep my profile private in part because I want to frustrate the heck out of targets if they find me. LOL.

Hey AJ, speaking of this app, do you know if anyone has posted a method of accessing target's public albums after getting the IDs through the app? Cuz if no one has, then I'll do it.
Logged
roxyb
Jr. Member
***

Karma: 49
Offline Offline

Posts: 72



« Reply #8 on: June 02, 2009, 08:29:07 PM »

I figured out the program.  Smiley  Is there a way to fusker using an album ID?  I've searched but couldn't find anything.  Thanks.
Logged
Angry Johnny
Global Moderator
Sr. Member
****************

Karma: 3849
Offline Offline

Posts: 614



« Reply #9 on: June 03, 2009, 03:53:57 PM »

don't know if anyone has posted a 'true' method, with all the changes recently.  I got sent an email from roxy, which, if she wants, she can post the link (uses burp suite), which shows how to brute force a random code (which I actually found to be unnecessary).  I know using the subj= command you can find all the album ids and maybe access the albums (have to figure a way around that).
Logged

Don't take life too seriously.  You'll never get out of it alive.
CornellWeasel
Honored Member
Full Member
********

Karma: 341
Offline Offline

Posts: 232



« Reply #10 on: June 03, 2009, 06:34:44 PM »

Seems my method is easier than the more complex (i.e., scary, for me anyway) things that's probably involved with Roxy's method. And just so no one gets his/her hopes up, what I'm talking about is just a method of viewing a full PUBLIC album on a private profile, after getting one of the photo URL links from Photostalker.

One of the benefits of my method (can I even call it "mine"?? I bet someone else's been doing this forever before me...), though not a breakthrough in codes or anything, is that it allows you to read comments because the album itself is accessed.

So, I guess I'll post it in a few min.
Logged
roxyb
Jr. Member
***

Karma: 49
Offline Offline

Posts: 72



« Reply #11 on: June 03, 2009, 08:46:29 PM »

don't know if anyone has posted a 'true' method, with all the changes recently.  I got sent an email from roxy, which, if she wants, she can post the link (uses burp suite), which shows how to brute force a random code (which I actually found to be unnecessary).  I know using the subj= command you can find all the album ids and maybe access the albums (have to figure a way around that).

Thanks for your help!  The method I found is at: http://securityninja.co.uk/blog/?p=198  I noticed public albums don't have an &l##### after them, so maybe that can be worked with.  I was wondering if fuskering would work to get in, like if someone took: album.php?aid=XXXX&id=XXXX&l#####.   Or can you find an album's &l part anyway?   I'm not sure how to fusker a link like that, burp suite goes way over my head. 

How do you use subj=command?  I haven't done that before. 

Looking forward to seeing CornellWeasel's method, too.
Logged
Angry Johnny
Global Moderator
Sr. Member
****************

Karma: 3849
Offline Offline

Posts: 614



« Reply #12 on: June 04, 2009, 08:11:31 AM »

http://www.facebook.com/photos.php?subj=XXXXXXXX where xxxxxxx is the id of the person who you want to see.
Logged

Don't take life too seriously.  You'll never get out of it alive.
rb9398
Jr. Member
**

Karma: 39
Offline Offline

Posts: 68



« Reply #13 on: June 04, 2009, 06:48:35 PM »

that code doesn't allow you to see the actual photos though huh?
Logged
roxyb
Jr. Member
***

Karma: 49
Offline Offline

Posts: 72



« Reply #14 on: June 05, 2009, 02:05:23 AM »

http://www.facebook.com/photos.php?subj=XXXXXXXX where xxxxxxx is the id of the person who you want to see.

Thanks!
Logged
Pages: 1 2 3 4 5 »   Go Up
  Print  
 
Jump to:  

Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC
.
Custom Search