Things You Need To Built An Awesome BlogGuide For Blogging + Designs + Widgets = Awesome Blog

Blogging Tips

Complete Guide For Blogging
(From Starting a Blog To Earning from It)

Learn More...

Blogger Templates

Awesome Blogger Themes for your blog - Nothing More!!!

Download Now!!!

Blogger Widgets

Spice Up Your Blogger Blog with Creatively Designed Widgets!

Check Now...

Hello, Welcome to BlogTipsNTricks. I'm Chandeep J. I've been doing web designing for 3 Years and this is where I share free themes, widgets and blogging tips which I learned from my experiance. More...

author

Hacking Facebook Account with just a text message

By
Advertisement

Can you ever imagine that a single text message is enough to hack any Facebook account without user interaction or without using any other malicious stuff like Trojans, phishingkeylogger etc. ?

Today we are going to explain you that how a UK based Security Researcher, "fin1te" is able to hack any Facebook account within a minute by doing one SMS.

Because 90% of us are Facebook user too, so we know that there is an option of linking your mobile number with your account, which allows you to receive Facebook account updates via SMS directly to your mobile and also you can login into your account using that linked number rather than your email address or username.

According to hacker, the loophole was in phone number linking process, or in technical terms, at file /ajax/settings/mobile/confirm_phone.php

This particular webpage works in background when user submit his phone number and verification code, sent by Facebook to mobile. That submission form having two main parameters, one for verification code, and second is profile_id, which is the account to link the number to.


Enter that code in the box or as confirmation_code parameter value and Submit the form. 


Facebook will accept that confirmation code and attacker's mobile number will be linked to victim's Facebook profile.

In next step hacker just need to go to Forgot password option and initiate the password reset request against of victim's account.

Facebook no longer accepting the profile_id parameter from the user end after receiving the bug report from the hacker.

In return, Facebook paying $20,000 to fin1te as Bug Bounty.

2 comments:

PC Tips, Trick, Internet Tricks, Hacking...

Total Pageviews

Like Us On Facebook

Enter your email address:

Delivered by Mail Posts, Inc.

Contact Form

Name

Email *

Message *

Follow Us

Powered by Blogger.

Followers

Blog Archive

Search This Blog

Wait! I want to get email updates, bring that back...
Connect with Trick Kit
RSS Twitter Facebook LinkedIn