[<prev] [next>] [day] [month] [year] [list]
Message-ID: <4C740416.9040200@gulftech.org>
Date: Tue, 24 Aug 2010 13:40:38 -0400
From: GulfTech Security Research <security@...ftech.org>
To: full-disclosure@...ts.grok.org.uk
Subject: Facebook Information Leakage ... Again
1. Navigate to the Facebook "Friend Finder" feature.
2. Click the "Upload Contact File" option in order to access the file
upload prompt.
3. Upload a contact file of ANY of the accepted formats that contains a
list of email addresses that you would like to enumerate.
4. Select the target email(s), and click "Invite to Join.
5. If the email you are targeting DOES have a restricted Facebook
profile then an email invite will not be sent, and a page which contains
a link to the Facebook profile associated with the target email address
to be enumerated will be displayed, thus allowing you to link the email
with the corresponding account.
Screens @
http://0x6a616d6573.blogspot.com/2010/08/facebook-information-leakage-again.html
~James
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists