main topics archive podcast connect
  • Have a suggestion?

  • *
  • *
  • *

REQUIRED READING

Notify Ricardo

When you finish something, notify Ricardo (Executive Editor) via a private DM through Twitter.

Okay Geek Traffic Traffic live stats Twitter activity Facebook Page Image compress app Tips & Guidelines Report a problem
← Previous Clean slate Next →
Wednesday
Aug112010

Facebook exploit reveals all of your user info (including profile photo)

A recent Facebook exploit has surfaced revealing everyone’s full name, profile picture and dignity. Right now, Facebook’s login system allows hackers to use a sneaky method in which they index random email adresses, and pick out the first and last names from the contact information. Then they brute force through Facebook’s login exploit to match the user info with the corresponding email address, even when users have configured their accounts to make that information private.

The information leak can be poked at by social-engineering scammers, phishers, or anyone who has ever been devious enough to want to know their victims. If the random email address belongs to any one of the 500 million active users on Facebook, the website will return the full name and picture associated with the account, this giving the spammers a face to follow.

Facebook users have no control over this, as this works even when you have set all privacy settings properly. Harvesting this data is very easy, as it can be easily bypassed by using a bunch of proxiesAtul Agarwal of Secfence Technologies

Obviously Facebook is developing fixes as I type, but I can’t help to wonder about all of the information these hackers have managed to gather. If you’re really paranoid, feel free to use a dummy avatar and fake name until the exploit is fixed.

Discussion Threads

Follow and Subscribe to Okay Geek - We always send our latest articles to Twitter, RSS, Facebook and more, as well as other awesome content we find interesting.

Related Posts Plugin for WordPress, Blogger...