HNHacker News
TopNewBestAskShowJobs

nico-roddz

232 karma · joined September 22, 2012

I help companies to increase his revenue and visibility through Internet. From startups to corporate business, for more than 5 years I had developed a proven track record of successful planning and execution of online marketing campaigns for a wide range of goals and objectives.

My blog: http://nicoroddz.com/ My linkedin profile: http://www.linkedin.com/in/nicoroddz

submissionscomments
nico-roddz··on More than 1MM Facebook accounts exposed
You're welcome!
nico-roddz··on More than 1MM Facebook accounts exposed
For the curious. Google results before patch:

http://nicoroddz.com/wp-content/uploads/2012/11/google-faceb...

nico-roddz··on More than 1MM Facebook accounts exposed
When you like or share a post in your newsfeed, you're sending a linkback to the original post.

So, if your newsfeed is public "to everyone" Google is able to crawl and index the content on it (discard the original post privacy settings)

nico-roddz··on More than 1MM Facebook accounts exposed
Thanks Matt,

My only concern is my account security (not money).

I found this issue with almost no technical knowledge, so the crazy thing is:

How many back doors should be over there ready to be exploited by spammers?

BTW, a big "report security issue" button on https://www.facebook.com/help/ would certainly help next time.

Thanks again,

Nico

nico-roddz··on More than 1MM Facebook accounts exposed
This is how everything started:

A friend forward me an email from a FB group notification

Something like:

http://www.facebook.com/n/?groups%[id here]%2Fpermalink%[id here]%2F&mid=[id here]&bcode=[id here]-mjoi&n_m=[email adress here]

When I clicked the url I got automatically logged into my friend's account.

So is definitely a Facebook security issue.

Then I tried some google searches to see if I could find some urls containing the parameters:

bcode= &email= n_m= mid=

Not a big deal, really.

nico-roddz··on More than 1MM Facebook accounts exposed
It's not an accident. You can even get fake urls indexed

http://www.seomofo.com/experiments/spam-search-results.html

nico-roddz··on More than 1MM Facebook accounts exposed
Use this Google's query:

inurl:bcode=[]+n_m=[] site:facebook.com

nico-roddz··on More than 1MM Facebook accounts exposed
Same thought. It must be really easy if you use an scraper and decode the urls.
nico-roddz··on More than 1MM Facebook accounts exposed
It's really weird.
nico-roddz··on More than 1MM Facebook accounts exposed
http://translate.google.com/translate?sl=es&tl=en&js...
nico-roddz··on More than 1MM Facebook accounts exposed
It's seems that Facebook uses robots.txt to block this pages

https://www.facebook.com/robots.txt

But, depending of the amount of inbound links, Google will index the urls anyway.

It's a common issue.