All Tricks
    • Home
    • Hacking
      • IDM UNIVERSAL CRACK
      • Bruit Force
      • Phishing FB new
      • Phishing Gmail New
      • Kali Tabnapping
      • Hack friends Profile
      • Hacking Tips
      • SSL Breaking Fb hack
      • Hack Wifi Win.
      • Website hack
    • Android
      • Root Android
      • Speed Up Android
      • Partition in SD
      • Run Kali on Android
      • Android on PC
      • Find Lost Android
      • Apple vs Android Vs Win
      • Apple vs Android Vs Win
    • Facebook
      • Autolikes
      • Page Rename
      • Rename FB ID
      • Empty Facebook ID
      • Blog to Facebook
      • IP changer Firefox
      • Bruit Force Attack
      • Xss Ijection FB
    • Youtube
      • Youtube -- 9xbuddy
      • Youtube -- Savefrom Net
      • Youtube -- catch videos
      • Youtube Downloader alltricks
      • Our Youtube Channel
    • Downloads
      • IDM UNIVERSAL CRACK POST
      • IDM CRACK UPDATE 11/2016
      • IDM Crack Direct Download 1
      • IDM crack Direct 2
      • Ease Us Recovery
    • Chat
    • DMCA ©
    • Contact us
      • Resume
      • CV
  • Home
  • Hacking
    • IDM UNIVERSAL CRACK
    • Bruit Force
    • Phishing FB new
    • Phishing Gmail New
    • Kali Tabnapping
    • Hack friends Profile
    • Hacking Tips
    • SSL Breaking Fb hack
    • Hack Wifi Win.
    • Website hack
  • Android
    • Root Android
    • Speed Up Android
    • Partition in SD
    • Run Kali on Android
    • Android on PC
    • Find Lost Android
    • Apple vs Android Vs Win
    • Apple vs Android Vs Win
  • Facebook
    • Autolikes
    • Page Rename
    • Rename FB ID
    • Empty Facebook ID
    • Blog to Facebook
    • IP changer Firefox
    • Bruit Force Attack
    • Xss Ijection FB
  • Youtube
    • Youtube -- 9xbuddy
    • Youtube -- Savefrom Net
    • Youtube -- catch videos
    • Youtube Downloader alltricks
    • Our Youtube Channel
  • Downloads
    • IDM UNIVERSAL CRACK POST
    • IDM CRACK UPDATE 11/2016
    • IDM Crack Direct Download 1
    • IDM crack Direct 2
    • Ease Us Recovery
  • Chat
  • DMCA ©
  • Contact us
    • Resume
    • CV

Wednesday, 16 April 2014

How to hack any Facebook account in under a minute, by sending just one SMS

 Parth Makadiya     10:21     FACEBOOK, HACK     No comments   



By Parth Makadiya
Share On Google+Add This To DeliciousTweet/ReTweet ThisShare on FacebookStumbleUpon ThisDigg This
Facebook mobile phoneA UK-based security researcher going by the name of “fin1te” has earned himself $20,000 after uncovering a way to hack into any account on Facebook, just by sending a mobile phone text message.
This should – obviously – have been impossible, but due to a weakness in Facebook’s tangled nest of millions and millions of lines in code, potentially hundreds of millions of accounts were vulnerable to hijacking through the simple technique.
Fin1te (real name Jack Whitten) has documented how the hack works on his blog.
The first thing to do is send the letter “F” in an SMS message to Facebook, as though you were legitimately registering your mobile phone with the social network. In the UK, the SMS shortcode for Facebook is 32665.
Send an SMS to Facebook
Facebook responds, via SMS, with an eight character confirmation code.
The normal sequence of events would be to enter that confirmation code into a Facebook form, and go on your merry way…
Facebook mobile activation form
But fin1te discovered that a vulnerability existed on that form, that could be exploited to use the confirmation code he had been sent by Facebook via SMS with *anyone* else’s account.
What fin1te had uncovered was that one of the elements of the mobile activation form contained, as a parameter, the user’s profile ID. That’s the unique number associated with your intended target’s account.
Profile ID parameter inside form
Change the profile ID that is sent by that form to Facebook, and the social network might be duped into thinking you are someone else linking a mobile phone to their account.
Therefore, the first step needed to hijack someone’s account in this way requires your victim’s unique Facebook profile ID.
If you don’t know what someone’s numeric profile ID is, you can always look it up usingfreely-available tools – they aren’t supposed to be a secret.
Find a Facebook profile ID
Sure enough, fin1te was able to replace the profile ID parameter sent by his browser to Facebook with the unique number of the account he wanted to access…
Facebook hack data
.. and within seconds his his mobile phone was sent an SMS confirming that he had successfully connected the device to the account.
Facebook confirmation SMS
Success. A Facebook account now has a third-party’s mobile phone number associated with it. Without any need for malware or phishing. All that was done was to send an SMS text message.
The final stage of the account hijacking is straightforward. Facebook allows you to log into its system using your mobile number rather than an email address if you want, so at login you enter the mobile phone number you have associated with your victim’s account, and request a password reset via SMS.
Reset code
Sure enough, fin1te discovered that Facebook duly sent him the password reset code for the account – meaning he could change the account’s password, and lock out its legitimate user.
This is an incredibly simple but powerful way to take over anybody’s Facebook account.
The good news is that fin1te disclosed the vulnerability responsibly to Facebook, rather than exploited it for malicious intentions or sold it to other parties. Facebook has fixed the problem so others can no longer take advantage of this serious security hole. For his troubles, Facebook awarded fin1te a hefty $20,000 worth of bug bounty and fixed the vulnerability.
But there’s no doubt that on the underground market, perhaps sold to cybercriminals or intelligence agencies, fin1te’s discovery could have earned him even more money.
Who knows what other serious security vulnerabilities may lay inside Facebook that haven’t been responsibly reported to the company’s security team?
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook
Newer Post Older Post Home

0 comments:

Post a Comment

Popular Posts

  • Internet Download Manager [IDM] Universal Crack Version
    By Parth Makadiya Note  : This crack has a built-in update function . Once IDM new version comes, you can update and apply crack ...
  • Windows Phone 8.1 Review: Gloriously Good Enough
    By Parth Makadiya Share On Google+ Add This To Delicious Tweet/ReTweet This Share on Facebook StumbleUpon This Digg This Microsof...
  • How to Open or Access Blocked Websites at Schools,College and Office Work
    By Parth Makadiya Share On Google+ Add This To Delicious Tweet/ReTweet This Share on Facebook StumbleUpon This Digg This N...
  • How to Hack WPA WiFi Passwords by Cracking the WPS PIN
    A flaw in  WPS , or  W iFi  P rotected  S etup, known about for over a year by  TNS , was finally exploited with proof...

Recent Posts

LightBlog

Categories

2 STEP VERIFICATION (1) 4.4 (2) 4.4.3 (1) 4G (1) ADSEAN (1) ANDROID (8) ANDROID ON PC (1) APK ON PC (2) BACKLINK (1) BLOCK (1) BLOG (2) BOOT (1) BOOTABLE (2) CCPROXY (1) Change (1) Chat (1) CMD (1) CRACK (1) CREATE YOUR OS (1) DATA (1) DOWNLOAD (1) DOWNLOADER (1) DUAL OS (1) error (1) EXTRA SECURE (1) FACEBOOK (5) FB (1) FEATURES (1) FIREFOX (1) fix error (1) FORMAT (1) FREE (1) GET TRAFFIC (1) GLASS (1) GOOGLE (2) HACK (12) HDD (1) HELP (3) HIDDEN PROFILE PICTURE (1) HOSTING (1) How to (1) IDM (2) INTERNET (1) INTERNET DOWNLOAD MANAGER (1) IOS VS WINDOWS VS ANDROID (1) KEYLOGGER (2) LINUX (1) Mac Adress (1) MOBILE (1) NEXUS (1) NOKIA ANDROID (1) NOTPAD (1) ONLINE (2) OPEN (1) OWN (1) PAGE (2) PATTERN (1) PC (2) PENDRIVE (1) PHISHING (1) PHONE (1) playstore (1) RECOVERY (2) RENAME (1) REVIEW (1) ROOT (5) SAMSUNG (1) SECURE (2) SHUT (1) Snuff (1) Social (1) solve error (1) SPEED (1) SPYWARE (1) TORRENT (1) TORRENT WITH IDM (1) TRACE (1) TRICKS (1) UPDATE (3) VIRUS (1) WEBCAM (1) WEBSITE (1) WEBSITES (2) widget (1) WIFI (4) WINDOWS (1) WINDOWS 7 (1) WINDOWS 8 (1) YOUTUBE (1)

Unordered List

  • Follow on Twitter
  • Like on Facebook
  • Subscribe on Youtube
  • Follow on Instagram

Pages

  • Home

Text Widget

Blog Archive

  • Home
  • About
  • Contact
  • 404
Powered by Blogger.

Category 4

Instagram

Ads Inside Post

Total Pageviews

Recent

Comment

Subscribe

Subscribe

Category 5

Event more news

Recent Posts

Breaking

Recent Posts

Contributors

  • Parth Makadiya
  • Top Android Applications

Contact Form

Name

Email *

Message *

  • Home
  • About
  • Contact
  • Features
  • _feature 1
  • _feature 2
  • __feature 3.1
  • __feature 3.2
  • __feature 3.3
  • _feature 4
  • _feature 5
  • Shortcodes
  • Documentation
  • Download this template

Labels

  • 2 STEP VERIFICATION
  • 4.4
  • 4.4.3
  • 4G
  • ADSEAN
  • ANDROID
  • ANDROID ON PC
  • APK ON PC
  • BACKLINK
  • BLOCK
  • BLOG
  • BOOT
  • BOOTABLE
  • CCPROXY
  • Change
  • Chat
  • CMD
  • CRACK
  • CREATE YOUR OS
  • DATA
  • DOWNLOAD
  • DOWNLOADER
  • DUAL OS
  • error
  • EXTRA SECURE
  • FACEBOOK
  • FB
  • FEATURES
  • FIREFOX
  • fix error
  • FORMAT
  • FREE
  • GET TRAFFIC
  • GLASS
  • GOOGLE
  • HACK
  • HDD
  • HELP
  • HIDDEN PROFILE PICTURE
  • HOSTING
  • How to
  • IDM
  • INTERNET
  • INTERNET DOWNLOAD MANAGER
  • IOS VS WINDOWS VS ANDROID
  • KEYLOGGER
  • LINUX
  • Mac Adress
  • MOBILE
  • NEXUS
  • NOKIA ANDROID
  • NOTPAD
  • ONLINE
  • OPEN
  • OWN
  • PAGE
  • PATTERN
  • PC
  • PENDRIVE
  • PHISHING
  • PHONE
  • playstore
  • RECOVERY
  • RENAME
  • REVIEW
  • ROOT
  • SAMSUNG
  • SECURE
  • SHUT
  • Snuff
  • Social
  • solve error
  • SPEED
  • SPYWARE
  • TORRENT
  • TORRENT WITH IDM
  • TRACE
  • TRICKS
  • UPDATE
  • VIRUS
  • WEBCAM
  • WEBSITE
  • WEBSITES
  • widget
  • WIFI
  • WINDOWS
  • WINDOWS 7
  • WINDOWS 8
  • YOUTUBE

Instagram

Labels

  • 2 STEP VERIFICATION
  • 4.4
  • 4.4.3
  • 4G
  • ADSEAN
  • ANDROID
  • ANDROID ON PC
  • APK ON PC
  • BACKLINK
  • BLOCK
  • BLOG
  • BOOT
  • BOOTABLE
  • CCPROXY
  • Change
  • Chat
  • CMD
  • CRACK
  • CREATE YOUR OS
  • DATA
  • DOWNLOAD
  • DOWNLOADER
  • DUAL OS
  • error
  • EXTRA SECURE
  • FACEBOOK
  • FB
  • FEATURES
  • FIREFOX
  • fix error
  • FORMAT
  • FREE
  • GET TRAFFIC
  • GLASS
  • GOOGLE
  • HACK
  • HDD
  • HELP
  • HIDDEN PROFILE PICTURE
  • HOSTING
  • How to
  • IDM
  • INTERNET
  • INTERNET DOWNLOAD MANAGER
  • IOS VS WINDOWS VS ANDROID
  • KEYLOGGER
  • LINUX
  • Mac Adress
  • MOBILE
  • NEXUS
  • NOKIA ANDROID
  • NOTPAD
  • ONLINE
  • OPEN
  • OWN
  • PAGE
  • PATTERN
  • PC
  • PENDRIVE
  • PHISHING
  • PHONE
  • playstore
  • RECOVERY
  • RENAME
  • REVIEW
  • ROOT
  • SAMSUNG
  • SECURE
  • SHUT
  • Snuff
  • Social
  • solve error
  • SPEED
  • SPYWARE
  • TORRENT
  • TORRENT WITH IDM
  • TRACE
  • TRICKS
  • UPDATE
  • VIRUS
  • WEBCAM
  • WEBSITE
  • WEBSITES
  • widget
  • WIFI
  • WINDOWS
  • WINDOWS 7
  • WINDOWS 8
  • YOUTUBE

Translate

Awesome

Category 5

Post Slider



Facebook

Comments

LightBlog
Adbox

Advertisement

About us

Popular Posts
  • Internet Download Manager [IDM] Universal Crack Version
    By Parth Makadiya Note  : This crack has a built-in update function . Once IDM new version comes, you can update and apply crack ...
  • Windows Phone 8.1 Review: Gloriously Good Enough
    By Parth Makadiya Share On Google+ Add This To Delicious Tweet/ReTweet This Share on Facebook StumbleUpon This Digg This Microsof...
  • How to Open or Access Blocked Websites at Schools,College and Office Work
    By Parth Makadiya Share On Google+ Add This To Delicious Tweet/ReTweet This Share on Facebook StumbleUpon This Digg This N...
  • How to Hack WPA WiFi Passwords by Cracking the WPS PIN
    A flaw in  WPS , or  W iFi  P rotected  S etup, known about for over a year by  TNS , was finally exploited with proof...
  • What is ROOT??
    Rooting - is it for me? Some Q&A By Parth Makadiya Share On Google+ Add This To Delicious Tweet/...
  • How To Root Android the Easy Way
    How To Root Android the Easy Way Click Here to Root Android By Parth Makadiya Share On Google+ Add This To Delicious Twe...
  • Creating Bootable Pen Drive Using Windows Command Prompt
    Making a pen drive bootable is possible in Windows7 & Windows8 operating system. Formatting a computer to install fresh Windows OS ...
  • Google Play Store Error 498 – 5 Ways to Fix it
    By Parth Makadiya Recently While Downloading Asphalt game on my Smartphone I got an  Error 498  in Google Play Store. To be Exact, the Err...
  • How to Recover Lost Data from a Formatted Drive in 7 Steps
    By  Parth Makadiya Last time we talked about when to use data recovery software and  10 features to look for when choosing recovery soft...
  • How to Install Windows XP from USB Flash/Pen Drive
    BY Parth Makadiya Share On Google+ Add This To Delicious Tweet/ReTweet This Share on Facebook StumbleUpon This Digg This Inst...

Sample Text

Copyright © All Tricks | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates