[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-disclosure] Facebook Information Leakage ... Again
- To: full-disclosure@xxxxxxxxxxxxxxxxx
- Subject: [Full-disclosure] Facebook Information Leakage ... Again
- From: GulfTech Security Research <security@xxxxxxxxxxxx>
- Date: Tue, 24 Aug 2010 13:40:38 -0400
1. Navigate to the Facebook "Friend Finder" feature.
2. Click the "Upload Contact File" option in order to access the file
upload prompt.
3. Upload a contact file of ANY of the accepted formats that contains a
list of email addresses that you would like to enumerate.
4. Select the target email(s), and click "Invite to Join.
5. If the email you are targeting DOES have a restricted Facebook
profile then an email invite will not be sent, and a page which contains
a link to the Facebook profile associated with the target email address
to be enumerated will be displayed, thus allowing you to link the email
with the corresponding account.
Screens @
http://0x6a616d6573.blogspot.com/2010/08/facebook-information-leakage-again.html
~James
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/