New Facebook Likejacker Anti-Confirm Dialog - Track Status Here

The Doctor

Senior Member
Joined
Dec 18, 2010
Messages
1,110
Reaction score
474
I was posting in a different thread someone made and it got closed because someone was trying to sell a script (That they didn't even have) in it. Apparently, Facebook has blocked clickjacking with their new popup. I was in the thread talking about how I think I have the answer to that. A long time ago I used to use a cross-browser exploit for a different marketing task. If it still works, it can be applied to this.

A friend of mine has the only remaining copy of the code. I asked him to dig it up and he's working on it. I've went ahead working on reconstructing it myself though because I think I remember how. So like I said. As long as the exploit still works, I can get around this block. If that happens, I'll make a marketplace thread here on BHW for it. It will be expensive but it's still basically giving it away. If I kept it to myself, I'd probably make more money but I like the prestige :P

I'm starting to get really tired so I won't have an answer today. I surely will tomorrow though. I've done some preliminary testing for other components that will be required and those checked out fine. If successful, this will be a new kind of clickjacker that I don't think has been done before. It will be very hard for FB to block. I'm not even sure that they could. At least I haven't been able to think of how they could yet.

Please, no-one message me asking me to sell you anything. I won't. Also, if you have your own script (I doubt it given what I have to do to get this to work), don't try to get people to buy it here because you'll just wind up getting banned from the forum.
 
if the script you are talking about is the same im thinking then i have it, if you don't find it let me know
 
I would definitely be interested in something like that. When you have it ready, please let us know.
 
Thanks for the update. I've been messing about with that damn popup all day trying to get rid of it.
 
"The Doctor
You were asking about a way to put an iframe in Facebook, in the closed thread, there is one... using FB tabs. Don't know if this will help you, but... you' ll find info about it in developer tool docs pages tabs, can't post a link here, sorry!
 
"The Doctor
You were asking about a way to put an iframe in Facebook, in the closed thread, there is one... using FB tabs. Don't know if this will help you, but... you' ll find info about it in developer tool docs pages tabs, can't post a link here, sorry!

Actually, that might be of some use depending on what I can do with it. Thanks. I just started work again. I have a bunch of Infiniproxy stuff to do first and then I'll get back to it.
 
Hi. I've checked this post about 20 times since its been posted to see if there is any progress.

I've tried myself but am hoping you have something better than I do.

The absolute basics... Liking any facebook url off of an external site now requires confirmation.
I've tried liking a non facebook url which didnt require confirmation then redirecting the url to a fb page. When I redirected via html/js nothing happened, the user liked the external url, nothing showed up in facebook, when I linted the page it still showed the first page not the end page.
When I redirected via http. If the person liked the non facebook page and the redirect was immediate the vistor would have to confirm in the facebook popup, if I redirected at a later point then linted the url the like was removed, so at first nothing happened as it was not a facebook url, when I redirected to the fb url the like was removed.

Trying to manipulate the confirmation... Putting the confirmation box in an iframe shouldn't be allowed to due to XSFR, there are ways to get around this but haven't helped. I managed to iframe the confirmation box using different methods, but what typically happened was that the confirmation box would just keep redirecting to another confirmation box until FB was the parent page. What it appears is that unless the parent URL is facebook, clicking on a like button which is liking a facebook url will need to be done within facebook.

I've tried with domains which are 6-7 years old, facebook pages which are just as old, websites which are using fb apps, pages which are currently running ads, facebook still required confirmation.

Why I have doubts so far, the like button is designed to be put on a non-facebook url so is allowed to be iframed within reason, The confirmation box isn't. If it was possible to manipulate the confirmation box you could use the same technique to get a vistor to like your facebook application without authorisation, which can make a request to profile information/email addresses, friend lists, photos, etc.

I did manage to make a tiny, absolutely miniscule amount of progress due to facebooks many integrations and user flow, I didn't manage like a page without confirmation but there was some activities I could still do.

The way I see it right now is there either has to be a way to like a page which doesn't require confirmation which can be used, but this is more down to understanding facebook from a ux perspective not from development or if there was a way around the confirmation box there would be a massive security issue.

Please, please, please tell me you have done better than me.
 
Hi. I've checked this post about 20 times since its been posted to see if there is any progress.

I've tried myself but am hoping you have something better than I do.

The absolute basics... Liking any facebook url off of an external site now requires confirmation.
I've tried liking a non facebook url which didnt require confirmation then redirecting the url to a fb page. When I redirected via html/js nothing happened, the user liked the external url, nothing showed up in facebook, when I linted the page it still showed the first page not the end page.
When I redirected via http. If the person liked the non facebook page and the redirect was immediate the vistor would have to confirm in the facebook popup, if I redirected at a later point then linted the url the like was removed, so at first nothing happened as it was not a facebook url, when I redirected to the fb url the like was removed.

Trying to manipulate the confirmation... Putting the confirmation box in an iframe shouldn't be allowed to due to XSFR, there are ways to get around this but haven't helped. I managed to iframe the confirmation box using different methods, but what typically happened was that the confirmation box would just keep redirecting to another confirmation box until FB was the parent page. What it appears is that unless the parent URL is facebook, clicking on a like button which is liking a facebook url will need to be done within facebook.

I've tried with domains which are 6-7 years old, facebook pages which are just as old, websites which are using fb apps, pages which are currently running ads, facebook still required confirmation.

Why I have doubts so far, the like button is designed to be put on a non-facebook url so is allowed to be iframed within reason, The confirmation box isn't. If it was possible to manipulate the confirmation box you could use the same technique to get a vistor to like your facebook application without authorisation, which can make a request to profile information/email addresses, friend lists, photos, etc.

I did manage to make a tiny, absolutely miniscule amount of progress due to facebooks many integrations and user flow, I didn't manage like a page without confirmation but there was some activities I could still do.

The way I see it right now is there either has to be a way to like a page which doesn't require confirmation which can be used, but this is more down to understanding facebook from a ux perspective not from development or if there was a way around the confirmation box there would be a massive security issue.

Please, please, please tell me you have done better than me.

We should chat. I'm on skype (th3d0ct0r001).
 
I've gotten to a point where I can make CORS requests (That I shouldn't be able to make) but I'm having trouble returning data from the requests. If I can return the data, I think I can fire the like by grabbing the necessary parameters and sending the proper request. There would be no confirm popup.
 
guys apologize but do not you mind that most likely writing these operations in public the facebook team can take the cue for any patch ???!
 
Just make it and open a BST thread lol, why build hype?
 
ninja couldn't do it, i doubt you guys can. he had a full team with him.

If you guys build a post liker I'd buy that off ya tho. ninjas support team not relying ;(

No offense to Ninja (Whoever that is) but computer security has no one point of authority that can ever conclude that something is secure. There is a way to do it. I can guarantee you that. Whether or not I will succeed is a different question but if this team can't do it, it's because they have prematurely admitted failure, not because it can't be done.

I have some good code going. I just need some help (Or more time alone) bringing it home.
 
Last edited:
No offense to Ninja (Whoever that is) but computer security has no one point of authority that can ever conclude that something is secure. There is a way to do it. I can guarantee you that. Whether or not I will succeed is a different question but if this team can't do it, it's because they have prematurely admitted failure, not because it can't be done.

I have some good code going. I just need some help (Or more time alone) bringing it home.

Sure, best of luck to you. Ninja was the guy who created the likejacker last year as a wp plugin. very respected dude but he claims it's not possible with FB's new algorithm. https://www.blackhatworld.com/seo/f...acebook-likes-to-your-pages-and-sites.720835/


I'll be following this thread! seriously gl.. :)
 
The old like jacking methods were just hiding an element and putting a button over it. Not that difficult really, just have to think of it. Getting around the actual security this time will be a lot harder with the checks Facebook put in. But if there is a cross domain request possible, then it could be doable. Depends a bit on the token checks also, whether the request will be verified by Facebook in the end.
 
I am able to iframe any fb link.... and have owercome the x frame browser settings and cros domain checks... but i am not able to pull the access tokens, so every link I iframe is displayed the same as the user is not loged in... does anyone know how to use user session cookies or any other metod, to overcome this??
One more thing... every other page load i get the x frame error...

I Allso think the like will have to come from within inside the facebook...
 
Back
Top