SlideShare a Scribd company logo
One Link
  Access the account without
  restriction with just one link

                    Anand K. Pandey
                    anandkpandey1@gmail.com
Facebook
• Social networking website
• Founded in February 2004 by Mark Zuckerberg
• Used to interact with friends, colleague and to make
  new friends
Facebook
•   Get 10 Billion hits per day
•   Second most visited site
•   More than 800 million active users
•   More then 250 million photos are uploaded daily
•   More than 900 million objects that people interact
    with
Number of active users
800
                                              750
700

600

500                               500

400                                                 Number of users (in
                         350                        million)
300

200

100            100
        50
  0
      2007   2008     2009     2010      2011
20 Minutes of Facebook
 Event                 Wall                  Comment
Invites                Posts                   Made
          14,84,000              15,87,000             1,02,08,000




 Link                  Photos                Status
Shared                Uploaded               Update

          10,00,000              27,16,000             18,51,000



                       Friend
Message                                      Tagged
                      Request
 Sent                                        Photos
                      Accepted
          27,16,000              19,72,000             13,23,000
Facebook in News
      • Massive hack/spam
        attack
      • Facebook tracks users
        activity
      • Anonymous threaten
        facebook
Facebook Security
• Unique Username
• Password
Facebook Security
• Check Point
Facebook Security
• Geo Location Restriction
Facebook Security
• Login review
Direct Link
• One single link
• Bypass all security points
   • Username
   • Password
   • Check points
   • Geo location restriction
Direct Link
When someone
• Comments on your photo
• Comments on your link
• Tags you
• Comments after you
Type 1
 http://m.facebook.com/photo.php?pid=xxxxxx&id=x
 xxxxxxxxxxxxxxx&mlid=xxxxxxxxxx&l=xxxxxxxx


• Parameters
  • pid – Photo id
  • id – FB id of user who commented
  • mlid – FB id of target user
  • l (s52giOr8) – Secret key
Type 2
 http://m.facebook.com/story.php?share_id=xxxxxx
 xxxxxxxxxx&mlid=xxxxxxxxxx&l=xxxxxxxx


• Parameters
  • Share_id – FB id for sharing the link
  • mlid – FB id of target user
  • l (s59gpZr8) – Secret key
Type 3
 http://fb.me/xxxxxxxxxxxxxx

• URL Shortening
• Contain 14 character random alpha-numeric
• Use specially for shortening the magic link
  sent via sms when someone comments on
  your link
• Database of random FB accounts with magic
  link
Type 4
 http://fb.me/p/xxxxxxxxxxxxxxx.yyyyyyyy

• URL Shortening
• Contain “id” and “l”
• Series of “x” are the FB id or user who
  commented on your photo
• Series of “y” is the special key
• Used specially for shortening the direct link sent
  via sms when someone comments on your photo
What you can do
• Brute-force or social engineer the direct URL
• Brute-force the shortened URL to hit random
  accounts with full access
• Remember the most important
  • FB user ID (mlid)
  • Secret key (l)
One link Facebook (Anand Pandey)
Email: anandkpandey1@gmail.com

Twitter: anand___pandey

Linkedin: http://in.linkedin.com/in/anandpandey1
One link Facebook (Anand Pandey)

More Related Content

PDF
Implementing Agile Marketing at e-FOOD.gr
PDF
Critical Infrastructure Security Talk At Null Bangalore 13 Feb 2010 Sundar N
PPTX
Fatcat Automatic Web SQL Injector by Sandeep Kamble
PPT
Six Keys to Securing Critical Infrastructure and NERC Compliance
PPTX
Infrastructure security
PPTX
Critical Infrastructure Security by Subodh Belgi
PDF
Shreeraj - Hacking Web 2 0 - ClubHack2007
PDF
Facebookのススメ
Implementing Agile Marketing at e-FOOD.gr
Critical Infrastructure Security Talk At Null Bangalore 13 Feb 2010 Sundar N
Fatcat Automatic Web SQL Injector by Sandeep Kamble
Six Keys to Securing Critical Infrastructure and NERC Compliance
Infrastructure security
Critical Infrastructure Security by Subodh Belgi
Shreeraj - Hacking Web 2 0 - ClubHack2007
Facebookのススメ

Similar to One link Facebook (Anand Pandey) (8)

PPT
Instagram: Using Influencers and NASCAR to Drive Traffic
PDF
Facebookビジネス活用最前線
PDF
Facebook Do you have to Like it?
PDF
Facebook Do you have to Like it?
PDF
Dienanh 110108231254-phpapp02
PDF
Instagram: Using Influencers and NASCAR to Drive Traffic
Facebookビジネス活用最前線
Facebook Do you have to Like it?
Facebook Do you have to Like it?
Dienanh 110108231254-phpapp02
Ad

More from ClubHack (20)

PDF
India legal 31 october 2014
PPTX
Cyberlaw by Mr. Pavan Duggal at ClubHack Infosec KeyNote @ Bangalore
PPT
Cyber Insurance
PPTX
Summarising Snowden and Snowden as internal threat
PDF
The Difference Between the Reality and Feeling of Security by Thomas Kurian
PDF
Stand Close to Me & You're pwned! Owning Smart Phones using NFC by Aditya Gup...
PPTX
Smart Grid Security by Falgun Rathod
PPTX
Legal Nuances to the Cloud by Ritambhara Agrawal
PPT
Infrastructure Security by Sivamurthy Hiremath
PDF
Hybrid Analyzer for Web Application Security (HAWAS) by Lavakumar Kuppan
PPTX
Hacking and Securing iOS Applications by Satish Bomisstty
PPTX
Content Type Attack Dark Hole in the Secure Environment by Raman Gupta
PDF
XSS Shell by Vandan Joshi
PDF
Clubhack Magazine Issue February 2012
PDF
ClubHack Magazine issue 26 March 2012
PDF
ClubHack Magazine issue April 2012
PDF
ClubHack Magazine Issue May 2012
PDF
ClubHack Magazine – December 2011
PDF
Scenatio based hacking - enterprise wireless security (Vivek Ramachandran)
PDF
Pentesting Mobile Applications (Prashant Verma)
India legal 31 october 2014
Cyberlaw by Mr. Pavan Duggal at ClubHack Infosec KeyNote @ Bangalore
Cyber Insurance
Summarising Snowden and Snowden as internal threat
The Difference Between the Reality and Feeling of Security by Thomas Kurian
Stand Close to Me & You're pwned! Owning Smart Phones using NFC by Aditya Gup...
Smart Grid Security by Falgun Rathod
Legal Nuances to the Cloud by Ritambhara Agrawal
Infrastructure Security by Sivamurthy Hiremath
Hybrid Analyzer for Web Application Security (HAWAS) by Lavakumar Kuppan
Hacking and Securing iOS Applications by Satish Bomisstty
Content Type Attack Dark Hole in the Secure Environment by Raman Gupta
XSS Shell by Vandan Joshi
Clubhack Magazine Issue February 2012
ClubHack Magazine issue 26 March 2012
ClubHack Magazine issue April 2012
ClubHack Magazine Issue May 2012
ClubHack Magazine – December 2011
Scenatio based hacking - enterprise wireless security (Vivek Ramachandran)
Pentesting Mobile Applications (Prashant Verma)
Ad

Recently uploaded (20)

PDF
A GUIDE TO GENETICS FOR UNDERGRADUATE MEDICAL STUDENTS
PDF
LNK 2025 (2).pdf MWEHEHEHEHEHEHEHEHEHEHE
PDF
RTP_AR_KS1_Tutor's Guide_English [FOR REPRODUCTION].pdf
PDF
GENETICS IN BIOLOGY IN SECONDARY LEVEL FORM 3
PDF
Trump Administration's workforce development strategy
PDF
SOIL: Factor, Horizon, Process, Classification, Degradation, Conservation
PPTX
1st Inaugural Professorial Lecture held on 19th February 2020 (Governance and...
PDF
Supply Chain Operations Speaking Notes -ICLT Program
PPTX
UV-Visible spectroscopy..pptx UV-Visible Spectroscopy – Electronic Transition...
PDF
What if we spent less time fighting change, and more time building what’s rig...
PPTX
Lesson notes of climatology university.
PDF
Paper A Mock Exam 9_ Attempt review.pdf.
PDF
Chinmaya Tiranga quiz Grand Finale.pdf
PDF
Classroom Observation Tools for Teachers
PPTX
UNIT III MENTAL HEALTH NURSING ASSESSMENT
PPTX
202450812 BayCHI UCSC-SV 20250812 v17.pptx
PPTX
Chinmaya Tiranga Azadi Quiz (Class 7-8 )
PPTX
CHAPTER IV. MAN AND BIOSPHERE AND ITS TOTALITY.pptx
PPTX
Unit 4 Skeletal System.ppt.pptxopresentatiom
PDF
medical_surgical_nursing_10th_edition_ignatavicius_TEST_BANK_pdf.pdf
A GUIDE TO GENETICS FOR UNDERGRADUATE MEDICAL STUDENTS
LNK 2025 (2).pdf MWEHEHEHEHEHEHEHEHEHEHE
RTP_AR_KS1_Tutor's Guide_English [FOR REPRODUCTION].pdf
GENETICS IN BIOLOGY IN SECONDARY LEVEL FORM 3
Trump Administration's workforce development strategy
SOIL: Factor, Horizon, Process, Classification, Degradation, Conservation
1st Inaugural Professorial Lecture held on 19th February 2020 (Governance and...
Supply Chain Operations Speaking Notes -ICLT Program
UV-Visible spectroscopy..pptx UV-Visible Spectroscopy – Electronic Transition...
What if we spent less time fighting change, and more time building what’s rig...
Lesson notes of climatology university.
Paper A Mock Exam 9_ Attempt review.pdf.
Chinmaya Tiranga quiz Grand Finale.pdf
Classroom Observation Tools for Teachers
UNIT III MENTAL HEALTH NURSING ASSESSMENT
202450812 BayCHI UCSC-SV 20250812 v17.pptx
Chinmaya Tiranga Azadi Quiz (Class 7-8 )
CHAPTER IV. MAN AND BIOSPHERE AND ITS TOTALITY.pptx
Unit 4 Skeletal System.ppt.pptxopresentatiom
medical_surgical_nursing_10th_edition_ignatavicius_TEST_BANK_pdf.pdf

One link Facebook (Anand Pandey)