Facebook Graph API robots.txt
graph.facebook.com
graph.facebook.com
http://graph.facebook.com/robot.stxt http://graph.facebook.com/r.o.b.o.t.s.t.x.t
This guy's actual short-URL is "robotstxt."
hxxp://graph.facebook.com/-----r.-o....b....o-t-s-t....x....t----....///////////___%%20%22/test/robots
will still output the same result as http://graph.facebook.com/robotstxt
If you're not logged in, my URL returns a 404: http://www.facebook.com/davetufts (or by ID: http://www.facebook.com/profile.php?id=603069147 )
Not a huge deal, because the graph page only shows my name and ID, but they are publicly accessible: http://graph.facebook.com/davetufts or http://graph.facebook.com/603069147
I'm not seeing a discrepancy here?
In fact, the json api gives out less information than the html frontend (e.g. all 18 pages you currently follow).
{ "error": { "type": "QueryParseException", "message": "Some of the aliases you requested do not exist: laden" } }
I'm not entirely sure about what you could do with this data, but it's there, for anyone to see.
Guess no one at facebook has noticed the vulnerability exposed with pretty usernames on facebook & ignoring "." in a different framework. (probably just following gmail usernames.)
you can set the userid as parameter and you get Mark Zuckerbergs Profile here : http://graph.facebook.com/4
Then you can simple count up to infinite to get the other profiles. The API has a Usage limit and blocks after a while