Friday 25 August 2017

Security: Facebook Hack - Make Your Account Secure

Disclaimer: This is for educational and informational purposes only.

Check video here: Facebook Security Tips in 2 Minutes

There's no easy way to hack a Facebook account nowadays. But believe me, there is still a way. Since the advent of the Bug Bounty Program of Facebook, lots of its vulnerabilities have been patched out immediately. This approach has made Facebook more secure than ever. Facebook phishing is one of the only ways to hack someone's account that is found to be working now since this relies on social engineering and does not rely on Facebook's design and security.

However, I have recently reported a vulnerability to Facebook but this was their last reply:


So, I thought that since Facebook does not see this as a vulnerability and won't do something about it, I decided to make people aware though this blog.

So how does this work? 

Steps:

1. Go to a user's Facebook Page.
2. Get the user's Facebook ID.
3. Open another browser and open Facebook.com
4. On the page, click on "Forgot Account" then paste the user's ID.
5. Initially Facebook will send a 6-digit code to the email of the account owner. Just ignore that and click "Did not get the code"
6. Other options will then show like below:

7. As you can see in the picture, the user an email associated with his/her account.
8. The key here is to guess / get the user's email addresses. The users usually just use their names combined with their day of birth, year, anniversary etc.

* suppose you have other ways to get the email address, go directly to step 13.

9. Some emails are hard to guess but on the picture you will have a clue. The first and the last characters of the email will appear together with asterisks in between like B***************7@yahoo.com.
10. So, the email begins with "B" and ends with "7" and the domain is yahoo.com. What's interesting also is that the number of asterisks represents the actual number of the hidden characters.

* yes you can zoom in and count them

11. Trial and Error - once you come up with a possible email address, go back to the Facebook page, open a new tab, go to Facebook and click "Forgot Account" then paste the email that you got.
12. If it matches that of the user's email, well and good. If not, try another combination.
13. If you got the correct email, go to the email provider. E.g if it is gmail go to gmail, yahoo if it is yahoo then paste the email address.
14. You'll want to see something like this:

15. This means that an email address is associated with a Facebook account but the email does not actually exist. If the email does exist, move on dude. It's even harder to hack a gmail or yahoomail account.
16. Create the email. Use it to reset the password of the user's Facebook account.


17. Finish. 

Note that additional Facebook security are in place; 2 Factor Verification and Defense in Depth Mechanisms like ID upload, Identify Recent Comments, Identify Pictures of Friends, Text a Code to Phone etc.

Generally, the idea is that whatever email addresses you have linked to any of your accounts, not only on Facebook, make sure that they are secure and make sure that they haven't expired yet.

Emails expire after 5 years when they are not opened.

So, let's make our accounts secure as much as possible.





3 comments:

  1. fastautoliker

    We did not hold any login information of the user with us. We only use your access token for exchanging your likes of your Facebook with others.
    Our website and auto like android services promotes users to gain automatic likes on their Facebook photos without having any restriction.

    ReplyDelete
  2. Hi. Can u help me how to recover my facebook account?

    ReplyDelete
  3. I want to use this opportunity to thank cybergoldenhacker professional service for a job well done ,I don't know its possible to spy on my partners phone remotely. If you need to check your spouse phone remotely without touching it contact : cybergoldenhacker at gmail dot com

    ReplyDelete

How to Disable Control + Alt + Delete on Log-in

Requiring the option to press the keys Ctrl + Alt + Del before you see your Windows log-in screen is actually a security setting which make...