Jump to content
nAb.h4x

Hacking Facebook Passwords like changing your own Password

Recommended Posts

Posted (edited)

Hacker found a way to hack and change your password like, just he used to change his own password. Confused ? Recently Facebook fix a very critical vulnerability on the tip of 'Sow Ching Shiong', an independent vulnerability researcher. Flaw allow anyone to reset the password of any Facebook user without knowing his last password

facebookchangepassword.png

Facebook having an option for compromised accounts at "https://www.facebook.com/hacked" , where Facebook ask one to change his password for further protection. This compromised account recovery page, will redirect you to another page at "https://www.facebook.com/checkpoint/checkpointme?f=[userid]&r=web_hacked"

hackingfacebookpassword.png

Researcher notice that the URL of the page having a parameter called "f" which represents your user ID and replacing the user ID with victim's user ID allow him to get into next page where attacker can reset the password of victim without knowing his last password.

The Vulnerability was very simple to execute, but now has been confirmed and patched by Facebook Security Team.

Sursa - TheHackerNews

Edited by nAb.h4x
  • Upvote 2
  • Downvote 1
Posted (edited)

:o Asa simplu ? Orice e vulnerabil dar totusi asta a fost o prostie din partea facebook.

De acum voi urmari mai cu atentie paginile facebook :))

Facebook having an option for compromised accounts at "https://www.facebook.com/hacked" , where Facebook ask one to change his password for further protection. This compromised account recovery page, will redirect you to another page at "https://www.facebook.com/checkpoint/checkpointme?f=[userid]&r=web_hacked"

Researcher notice that the URL of the page having a parameter called "f" which represents your user ID and replacing the user ID with victim's user ID allow him to get into next page where attacker can reset the password of victim without knowing his last password.

@io.kent Dupa cum explica, gaura de securitate permitea schimbarea parolei.

Edited by yoyois
Posted
Nu cred ca merge, sau trebuie sa sti parola veche, dar cand vrei sa furi un cont, daca nai idee de parola, nu ai nici o sansa asa

but now has been confirmed and patched by Facebook Security Team.

Posted

asta a fost o bresa buna in securitatea lor,asta la facebook,si la yahoo a fost una acum ceva vreme numita (data tamper)..eu cu metoda aia am reusit sa rezolv vreo 20 de conturi,evident persoanelor care meritau.dar din pacate a fost patchuita.asa mergeti la concursurile lor,sa le gasiti bresele din securitate,mergeti pe maruntis.,go go go,

PS:adevarat.tot ce este facut de om,mai devreme sau mai tz poate fi hakuit.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...