Jump to content
yo20063

Use facebook URL to spread your "stub"

Recommended Posts

Hi,

We are going to use facebook's redirector to spread our virus, bot, java drive by. The url that let us do this is

"https://www.facebook.com/l.php?u=", this is not an open redirector, but it will serve our purpose because 80% of people will trust it and will confirm without hesitation because it's primary url it's from facebook, and they trust facebook!

VIDEO

VIDEO2

As you can see, this works even if the user isn't logged into facebook.

I recommend that you shorten your URL "strategically" so you won't raise any suspicion in the confirmation dialog.

Happy phishing!

Edited by yo20063
Link to comment
Share on other sites

Yea, but since than, facebook has patched many of it's bugs and the original url in the facebook bug presented by you was "http://www.facebook.com/l.php?h=" and was if i'm not mistaken an open redirector.

This is something else dude....it's not that "mighty", it's shitier, but if you have imagination get's the job done.

I didn't copied anyone, or did research in this matter...just had an ideea.

Pardon my english...i'm drunk :)

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...