How I hacked unverified Facebook accounts
hak-it.blogspot.com
hak-it.blogspot.com
Another possibility is also not to log the user in after successful activation (i.e., mark the email as active, but don't give access to the account), but I've never seen anyone behaving like this.
Moreover, sensitive operations, like changing settings or deleting the account, should be password-protected (so that, even if logged in, the attacker couldn't damage too much).
Anything else that I'm missing?
I wonder how many users don't ever verify their email address though... Couldn't facebook instead just make you verify it? i.e. not allow / limit use of service until you've verified your email address?
What I wanted to ask is what info Facebook wants from you before paying out, besides your Paypal email address of course.
$ seq -w -s "\n" 99999 > outfile.txt
also, burp has a generator built into the intruder to create these types of payloads. it is very powerful.