{"id":8552,"date":"2013-02-22T14:36:38","date_gmt":"2013-02-22T22:36:38","guid":{"rendered":"http:\/\/www.perivision.net\/wordpress\/?p=8552"},"modified":"2013-02-22T14:42:28","modified_gmt":"2013-02-22T22:42:28","slug":"how-to-hack-facebook-though-oauth","status":"publish","type":"post","link":"https:\/\/www.perivision.net\/wordpress\/2013\/02\/how-to-hack-facebook-though-oauth\/","title":{"rendered":"How to hack Facebook through OAuth"},"content":{"rendered":"<p>Well, this not good for facebook. Your worried about your privacy?\u00a0 Try to use all the tools to protect yourself that facebook provides?\u00a0 May not matter.\u00a0 Check this out below.<\/p>\n<p>In <a href=\"http:\/\/www.nirgoldshlager.com\/2013\/02\/how-i-hacked-facebook-oauth-to-get-full.html\">Nir Goldshlager<\/a>&#8216; post, he outlines, almost step by step, how you can perform the same &#8216;hack&#8217;.\u00a0 Facebook claims to have fixed this, but Nir says there are others and he will post them soon.<\/p>\n<blockquote><p>I decided to share one of my favorite flaws i discovered in\u00a0 <a href=\"http:\/\/facebook.com\/\" target=\"_blank\">facebook.com<\/a>,<\/p>\n<div>This flaw allowed me to take a full control over any Facebook account,By exploiting this flaw I could steal unique access tokens that provides me full control over any Facebook account,<\/div>\n<div dir=\"ltr\">\u00a0 <b>\u00a0<\/b><\/div>\n<div dir=\"ltr\"><b>just to clarify\u00a0there is no need for any installed apps on the victim&#8217;s account, Even if the victim never allowed any application in his\u00a0 Facebook account, I could still be getting full permissions (This bug works on any browser)<\/b><\/div>\n<div>To make this exploit work, The victim only need to visit a webpage,<br \/>\nSo OAuth is used by Facebook to communicate between Applications and Facebook users, Usally users must allow\/accept the application request to access their account before the communication can start.<\/div>\n<div>Any Facebook application might ask for different permissions,<\/div>\n<div><span style=\"text-decoration: underline;\"><b>For example:\u00a0<\/b><\/span><\/p>\n<div><\/div>\n<div>Diamond Dash,Texas Holdem Poker only have permission to basic information and post on user&#8217;s wall,<\/div>\n<div><\/div>\n<div><a href=\"http:\/\/2.bp.blogspot.com\/-D5fir9zyqpk\/USYahKFli9I\/AAAAAAAAAno\/nEOlbWoDP8A\/s1600\/nadia+oauth+diamond+dash.jpg\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"http:\/\/2.bp.blogspot.com\/-D5fir9zyqpk\/USYahKFli9I\/AAAAAAAAAno\/nEOlbWoDP8A\/s320\/nadia+oauth+diamond+dash.jpg\" width=\"320\" height=\"147\" border=\"0\" \/><\/a><\/div>\n<div><\/div>\n<div><\/div>\n<div>\n<p>I found a way in to get a full permissions (read inbox, outbox, manage pages, manage ads, read private photos, videos,etc..) over the victim account even without any installed apps on the victim&#8217;s account,<\/p>\n<\/div>\n<p>Another advantage in the flaw I found is that there is no &#8220;Expired date&#8221; of the Token like there would be on any other application usage, In my attack the token never expires unless the victim change his password :),<\/p>\n<\/div>\n<\/blockquote>\n<div class=\"SPOSTARBUST-Related-Posts\"><H3>Related Posts<\/H3><ul class=\"entry-meta\"><li class=\"SPOSTARBUST-Related-Post\"><a title=\"Ray-Ban Facebook Glasses: Good, Bad, and not quite the AR\" href=\"https:\/\/www.perivision.net\/wordpress\/2021\/09\/ray-ban-facebook-glasses-good-bad-and-not-quite-the-ar\/\" rel=\"bookmark\">Ray-Ban Facebook Glasses: Good, Bad, and not quite the AR<\/a><\/li>\n<li class=\"SPOSTARBUST-Related-Post\"><a title=\"How to overclock your calculator\" href=\"https:\/\/www.perivision.net\/wordpress\/2014\/06\/how-to-overclock-your-calculator\/\" rel=\"bookmark\">How to overclock your calculator<\/a><\/li>\n<li class=\"SPOSTARBUST-Related-Post\"><a title=\"WHY would facebook buy Oculus.. Unless&#8230; Second life a la Facebook?\" href=\"https:\/\/www.perivision.net\/wordpress\/2014\/03\/why-would-facebook-buy-oculus-unless-second-life-a-la-facebook\/\" rel=\"bookmark\">WHY would facebook buy Oculus.. Unless&#8230; Second life a la Facebook?<\/a><\/li>\n<li class=\"SPOSTARBUST-Related-Post\"><a title=\"Your Twitter app suddenly does not work with OAuth, could be your database\" href=\"https:\/\/www.perivision.net\/wordpress\/2014\/02\/your-twitter-app-suddenly-does-not-work-with-oauth-could-be-your-database\/\" rel=\"bookmark\">Your Twitter app suddenly does not work with OAuth, could be your database<\/a><\/li>\n<li class=\"SPOSTARBUST-Related-Post\"><a title=\"First Choice Cola&#8217;s Free Ride &#8211; Augmented Reality Facebook game\" href=\"https:\/\/www.perivision.net\/wordpress\/2013\/01\/first-choice-cola-freeride-augmented-reality-facebook-game\/\" rel=\"bookmark\">First Choice Cola&#8217;s Free Ride &#8211; Augmented Reality Facebook game<\/a><\/li>\n<\/ul><\/div>","protected":false},"excerpt":{"rendered":"<p>Well, this not good for facebook. Your worried about your privacy?\u00a0 Try to use all the tools to protect yourself that facebook provides?\u00a0 May not matter.\u00a0 Check this out below. In Nir Goldshlager&#8216; post, he outlines, almost step by step, how you can perform the same &#8216;hack&#8217;.\u00a0 Facebook claims to have fixed this, but Nir&hellip; <a class=\"read-more\" href=\"https:\/\/www.perivision.net\/wordpress\/2013\/02\/how-to-hack-facebook-though-oauth\/\">Read More<\/a><\/p>\n","protected":false},"author":2,"featured_media":5643,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21,59],"tags":[463,1994,688],"class_list":["post-8552","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fail","category-tips","tag-facebook","tag-hacks","tag-oauth"],"jetpack_featured_media_url":"https:\/\/www.perivision.net\/wordpress\/wp-content\/uploads\/2011\/07\/facebook-locked.jpg","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pjzQD-2dW","_links":{"self":[{"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/posts\/8552","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/comments?post=8552"}],"version-history":[{"count":3,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/posts\/8552\/revisions"}],"predecessor-version":[{"id":8555,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/posts\/8552\/revisions\/8555"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/media\/5643"}],"wp:attachment":[{"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/media?parent=8552"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/categories?post=8552"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/tags?post=8552"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}