|
Full Disclosure
mailing list archives
Facebook Information Leakage ... Again
From: GulfTech Security Research <security () gulftech org>
Date: Tue, 24 Aug 2010 13:40:38 -0400
1. Navigate to the Facebook "Friend Finder" feature.
2. Click the "Upload Contact File" option in order to access the file
upload prompt.
3. Upload a contact file of ANY of the accepted formats that contains a
list of email addresses that you would like to enumerate.
4. Select the target email(s), and click "Invite to Join.
5. If the email you are targeting DOES have a restricted Facebook
profile then an email invite will not be sent, and a page which contains
a link to the Facebook profile associated with the target email address
to be enumerated will be displayed, thus allowing you to link the email
with the corresponding account.
Screens @
http://0x6a616d6573.blogspot.com/2010/08/facebook-information-leakage-again.html
~James
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
By Date
By Thread
Current thread:
- Facebook Information Leakage ... Again GulfTech Security Research (Aug 24)
|