She-geeks Forum
May 22, 2012, 01:12:04 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: Get the Hacker's Underground Handbook:
http://www.she-geeks.com/hackers-underground-handbook1.html
 
   Home   Help Search Login Register  
Pages: 1   Go Down
  Print  
Author Topic: There is a way to see private pics  (Read 809 times)
0 Members and 1 Guest are viewing this topic.
peekaboo17
Full Member
****

Karma: 49
Offline Offline

Posts: 77



« on: May 17, 2011, 08:13:12 PM »

since the forum is dead I though i would contribute, I wish I was more internet savy to get into this but all I can do is give the heads up here is the info, hope I can get more info soon, this is from GUG:

So it seems there IS a new Facebook haq out there that will allow pictures to be viewed on private Facebook accounts. According to an article posted in a U.K. tech-news website:
theregister.co.uk wrote:


...police are investigating the Facebook URL vulnerability demonstrated by Christian Heinrich on Sunday, in which the security researcher demonstrated gaining access to privacy-protected Facebook photographs of a rival researcher’s wife.

It would appear that this confirms for now at least until Facebook fixes it, you CAN view private Facebook pictures.. If/as we get more information, we will surely post it..
Logged
angelfire
Honored Member
Full Member
**********

Karma: 622
Offline Offline

Posts: 212



« Reply #1 on: May 19, 2011, 08:45:10 AM »

A bit more on this... This excerpt is from the May 17 article in the Sydney Morning Herald, which made the hacking incident known to the general public (and also led to the immediate arrest of the author, Ben Grubb, for questioning in the case in Australia):

http://www.smh.com.au/technology/security/security-experts-go-to-war-wife-targeted-20110517-1eqsm.html

Quote
In his presentation shown to audience members, Heinrich demonstrated how he had, over about seven days, extracted the privacy-protected Facebook photos of Gatford's wife via Facebook's CDN. One photo was of Gatford sitting on the floor next to one of his children.

Heinrich blurred out the child's face but left Gatford's in.

Over the seven days or so Heinrich ran a program on his computer to guess the URL of a photo. It needed two inputs in the demonstration given to Fairfax Media - the friend ID and X. The value X was what Heinrich got the computer to guess, getting it to guess daily from about 0 to 200,000.

There IS a way, but it involves a special computer program and a week's worth of letting it run through 200,000 possibilities to guess a URL component (album or pic ID?). Now that this story is in the news, I wonder if Facebook will tinker with things again to try and prevent future hacking with this method, or at least to appear to be taking the matter seriously?
Logged
Pages: 1   Go Up
  Print  
 
Jump to:  

Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC
.
Custom Search