Facebook লেবেলটি সহ পোস্টগুলি দেখানো হচ্ছে৷ সকল পোস্ট দেখান
Facebook লেবেলটি সহ পোস্টগুলি দেখানো হচ্ছে৷ সকল পোস্ট দেখান



Facebook is one of the most widely used social networking site with more than 750 million users, as a reason if which it has become the number 1 target of hackers, I have written a couple of post related to facebook hacking here at RHA, In my previous post which I wrote in 2010 related to facebook hacking and security 4 ways on How to hack facebook password, I mentioned the top methods which were used by hackers to hack facebook accounts, however lots of things have changed in 2011, Lots of methods have went outdated or have been patched up by facebook and lots of new methods have been introduced, So in this post I will write the top 10 methods how hackers can hack facebook accounts in 2010.


10 Ways How Hackers Can Hack Facebook Accounts In 2011

So here are the top 10 methods which have been the most popular in 2011:


1. Facebook Phishing 




Phishing still is the most popular attack vector used for hacking facebook accounts, There are variety of methods to carry out phishing attack, In a simple phishing attacks a hacker creates a fake login page which exactly looks like the real facebook page and then asks the victim to login into that page, Once the victim logins through the fake page the victims "Email Address" and "Password" is stored in to a text file, The hacker then downloads the text file and get's his hands on the victims credentials.

I have explained the step by step phishing process in my post below:

2. Keylogging 

Keylogging, according to me is the easiest way to hack a facebook password, Keylogging sometimes can be so dangerous that even a person with good knowledge of computers can fall for it. A keylogger is basically a small program which once is installed on victims computer will record every thing which victim types on his/her computer. The logs are then send back to the attacker by either FTP or directly to hackers email address. I have dedicated a half of my newsest book "An introduction to keyloggers, RATS And Malware" to this topic.

Ethical Hacking Book
3. Stealers 



Almost 80% percent people use stored passwords in their browser to access the facebook, This is is quite convenient but can sometimes be extremely dangerous, Stealers are software's specially designed to capture the saved passwords stored in the victims browser, Stealers once FUD can be extremely powerful. If you want to how stealers work and how you can set up your own one?, Kindly refer the book above.


4. Session Hijacking




Session Hijacking can be often very dangerous if you are accessing Facebook on a http:// connection, In a Session Hijacking attack a hacker steals the victims browser cookie which is used to authenticate a user on a website and uses to it to access victims account, Session hijacking is widely used on Lan's. I have already written a three part series on How session hijacking works? and also a separate post on Facebook session hijacking.


5. Sidejacking With Firesheep


Sidejacking attack went common in late 2010, however it's still popular now a days, Firesheep is widely used to carry out sidejacking attacks, Firesheep only works when the attacker and victim is on the same wifi network. A sidejacking attack is basically another name for http session hijacking, but it's more targeted towards wifi users.

To know more about sidejacking attack and firesheep, read the post mentioned below:

6. Mobile Phone Hacking



Millions of Facebook users access Facebook through their mobile phones. In case the hacker can gain access to the victims mobile phone then he can probably gain access to his/her Facebook account. Their are lots of Mobile Spying softwares used to monitor a Cellphone.

The most popular Mobile Phone Spying softwares are:

1. Mobile Spy
2. Spy Phone Gold

7. DNS Spoofing 


If both the victim and attacker are on the same network, an attacker can use a DNS spoofing attack and change the original facebook.com page to his own fake page and hence can get access to victims facebook account.




8. USB Hacking 

Usb password stealer
If an attacker has physical access to your computer, he could just insert a USB programmed with a function to automatically extract saved passwords in the browser, I have also posted related to this attack which you can read by accessing the link below:
9. Man In the Middle Attacks


If the victim and attacker are on the same lan and on a switch based network, A hacker can place himself b/w the client and the server or he could also act as a default gateway and hence capturing all the traffic in between, ARP Poisoning which is the other name for man in the middle attacks is a very broad topic and is beyond the scope of this article, We have written a couple of articles on man in the middle attacks which canb be accessed from the links mentioned below:
If you are really interested in learning how man in the middle attacks, you can view the presentation below by oxid.it.

10. Botnets 


Botnets are not commonly used for hacking facebook accounts, because of it's high setup costs, They are used to carry more advanced attacks, A botnet is basically a collection of compromised computer, The infection process is same as the keylogging, however a botnet gives you, additional options in for carrying out attacks with the compromised computer. Some of the most popular botnets include Spyeye and Zeus.


Facebook Hacking Course




Facebook hacking course is a facebook security course created by me, which tells you exactly how how hackers can compromise your facebook accounts and what can you do to protect your facebook accounts from getting hacked.

Click here to get access to the course


Facebook Hack – View photo albums of non-friends

৮/২৮/২০১১ ০৫:২৩:০০ PM | , | 0 comments »

A new facebook exploit allows anyone to access any photo album of non-friends as long as you have the link.
Facebook Photo Exploit
By following the simple steps shown in above image, you can bypass the security of Facebook and view photos of others online.

Facebook iPad App Surfaces in iPhone App, Blogger Says

৮/২৪/২০১১ ০১:১৫:০০ PM | | 0 comments »

 
screenshots via TechCrunchThe official Facebook iPad application is expected to have a left-side navigation menu and full-screen photo viewing.


Last month I wrote about an official Facebook iPad application, which is expected to be available soon. The app still has not made its formal debut, but MG Siegler of the blog TechCrunch, said he found the code for the app hidden inside Facebook’s iPhone app.
Mr. Siegler, who said he gained access to the new app by sifting through the Facebook iPhone code, could not confirm if the features he discovered showed the final version for the app, but in a blog post, offered some details of the interface and design.
A Facebook spokesperson said via e-mail, “We’re constantly working on new products and features but have nothing new to announce at this time.”
Mr. Siegler said the application’s navigation was “great.” Compared with the company’s official iPhone application, the iPad version offers a left-side menu system and the design takes full advantage of the large screen real estate available on the Apple tablet, he said.
As I discussed in my previous post, Mr. Siegler said that the photo-viewing feature within the app was highly optimized for the iPad, and that navigating Facebook photos felt natural and very similar to using the built-in photo viewer on the iPad. The new application is also primarily built using HTML5, the Web programming language.
It is still unclear when the official Facebook iPad will be formally unveiled. Mark Zuckerberg, Facebook’s founder and chief executive, recently said the company planned to introduce a number of new products in the coming weeks. We can only hope the iPad app is among them.
You can see dozens of detailed photos of the new application on TechCrunch.

Facebook Aims to Simplify Privacy Settings

৮/২৪/২০১১ ০১:০৫:০০ PM | | 0 comments »

 
Facebook is simplifying privacy controls for posts.
 
Didn’t mean for your boss to see a picture of you on the beach that day you called in sick? Maybe you hadn’t meant for the police to know you were mobilizing your friends to join a public protest? Had you bargained on your high school principal seeing Facebook photographs that they considered so risqué they kicked you off the cheerleading squad?
Sharing online, as social media enthusiasts are learning, can have all sorts of unintended consequences offline.
Now Facebook says it wants to help you get a better grip on what you share. On Tuesday the company revealed changes to its privacy settings that it says are designed to more clearly show who knows what about your life on the Internet. The changes will take effect Thursday.
Every time you post a picture, update your status or add any other content to your Facebook page, you will be able to more easily specify who can see it: friends, everyone on the Internet, or a customized group. These will be indicated by icons that replace the current, more complicated padlock menu.
What is now called “everyone” in those settings will instead be called “public.” Facebook executives say they want to dispel any doubts about what the setting means. If you click “public,” that means anyone who is online can see it, including perfect strangers – or, worse, parents, prospective employers and your ex-wife’s divorce lawyers.
Similar settings will now appear next to other material you have posted, like your work history or photo albums, so you will no longer need to click to pages full of privacy options to change them.
Chris Cox, vice president for product at Facebook, put it this way: “We want to make this stuff unmistakably clear.”
No doubt the company also wants to diminish the possibility of legislation, investigation or litigation stemming from complicated or confusing privacy settings. And with mounting competition from other social networking sites, namely Google+, which emphasizes more compartmentalized communications to different sets of friends and acquaintances, Facebook is also keen to keep its customers’ trust.
“Your profile should feel like your home on the Web,” the company said in a blog post. “You should never feel like stuff appears there that you don’t want, and you shouldn’t ever wonder who can see anything that shows up there.”
That includes tagged pictures. The site will now let you approve every picture in which you are tagged before it appears on your profile page. No longer will an unflattering or compromising photograph of you show up there without your consent, though the publisher of the photograph can still post it on his or her own page.
The changes point to some of the company’s growing pains, in which mass appeal can sometimes be a bit of a liability. Facebook is used today by 750 million people all over the world, with varying degrees of knowledge about what it means to have a life online. Company officials say they hope the latest changes will demystify privacy settings and ensure that Facebook users are never “surprised,” as Mr. Cox put it, by what others can see about them.
“We need to offer fine granularity in order to be a universally usable tool,” he added. With the new changes, “it’s more visual and prominent who the audience is.”
Indeed, company officials say feedback from users suggested that pictures work better than words. So now, icons help you select who can see what. “Public” is represented by a globe; “friends” by a pair of heads.
Whether users will find the changes more inviting or simpler remains to be seen -– as does whether they will opt to be more or less private. Facebook declined to share statistics on its users’ current privacy settings.

Facebook Like Button

৮/২২/২০১১ ০৭:৪৫:০০ PM | | 0 comments »

The Like button lets a user share your content with friends on Facebook. When the user clicks the Like button on your site, a story appears in the user’s friends’ News Feed with a link back to your website.
When your Web page represents a real-world entity, things like movies, sports teams, celebrities, and restaurants, use the Open Graph protocol to specify information about the entity. If you include Open Graph tags on your Web page, your page becomes equivalent to a Facebook page. This means when a user clicks a Like button on your page, a connection is made between your page and the user. Your page will appear in the “Likes and Interests” section of the user’s profile, and you have the ability to publish updates to the user. Your page will show up in same places that Facebook pages show up around the site (e.g. search), and you can target ads to people who like your content.
There are two Like button implementations: XFBML and Iframe. The XFBML version is more versatile, but requires use of the JavaScript SDK. The XFBML dynamically re-sizes its height according to whether there are profile pictures to display, gives you the ability (through the Javascript library) to listen for like events so that you know in real time when a user clicks the Like button, and it always gives the user the ability to add an optional comment to the like. If users do add a comment, the story published back to Facebook is given more prominence.
To get started, just use the configurator below to get code to add to your site.
Step 1 – Get Like Button Code
URL to Like (?)
Send Button (XFBML Only) (?)
Send Button
Layout Style (?)
Width (?)
Show Faces (?)
Show faces
Verb to display (?)
Color Scheme (?)
Font (?)
Get Code
Attributes
href – the URL to like. The XFBML version defaults to the current page.
send – specifies whether to include a Send button with the Like button. This only works with the XFBML version.
layout – there are three options.
standard – displays social text to the right of the button and friends’ profile photos below. Minimum width: 225 pixels. Default width: 450 pixels. Height: 35 pixels (without photos) or 80 pixels (with photos).
button_count – displays the total number of likes to the right of the button. Minimum width: 90 pixels. Default width: 90 pixels. Height: 20 pixels.
box_count – displays the total number of likes above the button. Minimum width: 55 pixels. Default width: 55 pixels. Height: 65 pixels.
show_faces – specifies whether to display profile photos below the button (standard layout only)
width – the width of the Like button.
action – the verb to display on the button. Options: ‘like’, ‘recommend’
font – the font to display in the button. Options: ‘arial’, ‘lucida grande’, ‘segoe ui’, ‘tahoma’, ‘trebuchet ms’, ‘verdana’
colorscheme – the color scheme for the like button. Options: ‘light’, ‘dark’
ref – a label for tracking referrals; must be less than 50 characters and can contain alphanumeric characters and some punctuation (currently +/=-.:_). The ref attribute causes two parameters to be added to the referrer URL when a user clicks a link from a stream story about a Like action:
fb_ref – the ref parameter
fb_source – the stream type (‘home’, ‘profile’, ‘search’, ‘other’) in which the click occurred and the story type (‘oneline’ or ‘multiline’), concatenated with an underscore.
Step 2 – Get Open Graph Tags
Title (?)
Type (?)
URL (?)
Image (?)
Site name (?)
Admin (?)
Get Tags
Open Graph Tags
Open Graph tags are tags that you add to the of your website to describe the entity your page represents, whether it is a band, restaurant, blog, or something else.
An Open Graph tag looks like this:
If you use Open Graph tags, the following six are required:
og:title – The title of the entity.
og:type – The type of entity. You must select a type from the list of Open Graph types.
og:image – The URL to an image that represents the entity. Images must be at least 50 pixels by 50 pixels. Square images work best, but you are allowed to use images up to three times as wide as they are tall.
og:url – The canonical, permanent URL of the page representing the entity. When you use Open Graph tags, the Like button posts a link to the og:url instead of the URL in the Like button code.
og:site_name – A human-readable name for your site, e.g., “IMDb”.
fb:admins or fb:app_id – A comma-separated list of either the Facebook IDs of page administrators or a Facebook Platform application ID. At a minimum, include only your own Facebook ID.
More information on Open Graph tags and details on Administering your page can be found on the Open Graph protocol documentation .
FAQ
How do I know when a user clicks a Like button?
If you are using the XFBML version of the button, you can subscribe to the ‘edge.create’ event through FB.Event.subscribe.
When will users have the option to add a comment to the like?
If you are using the XFBML version of the Like button, users will always have the option to add a comment. If you are using the Iframe version of the button, users will have the option to comments if you are using the ‘standard’ layout with a width of at least 400 pixels. If users do add a comment, the story published back to Facebook is given more prominence.
What analytics are available about the Like button?
If you visit facebook.com/insights and register your domain, you can see the number of likes on your domain each day and the demographics of who is clicking the Like button.
Can I link the Like button to my Facebook page?
Yes. Simply specify the URL of your Facebook page in the href parameter of the button.
What is the best way to know which Like button on my page generated the traffic?
Add the ‘ref’ parameter to the plugin (see “Attributes” above).
Examples:
When a user clicks a link back to your website, we will pass back both the ref value as a fb_ref parameter and the fb_source parameter in the referrer URL. Example:
http://www.facebook.com/l.php?fb_ref=top_left&fb_source=profile_oneline
Aggregated stream stories contain all ref parameters, concatenated with commas.
When does Facebook scrape my page?
Facebook needs to scrape your page to know how to display it around the site.
Facebook scrapes your page every 24 hours to ensure the properties are up to date. The page is also scraped when an admin for the Open Graph page clicks the Like button and when the URL is entered into the Facebook URL Linter. Facebook observes cache headers on your URLs – it will look at “Expires” and “Cache-Control” in order of preference. However, even if you specify a longer time, Facebook will scrape your page every 24 hours.
The user agent of the scraper is: “facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)”
How do I display the Like button in different languages?
If you are using the XFBML version include the language code when you instantiate the library. Replace ‘en_US’ in this line with the correct locale code:
‘//connect.facebook.net/en_US/all.js’;
If you are using the Iframe version include a locale parameter with the proper country code in the src URL. Example:
src=”http://www.facebook.com/plugins/like.php?locale=fr_FR&…”
You may need to adjust the width of the Like button to accommodate different languages.
What makes up the number shown on my Like button?
The number shown is the sum of:
The number of likes of this URL
The number of shares of this URL (this includes copy/pasting a link back to Facebook)
The number of likes and comments on stories on Facebook about this URL
The number of inbox messages containing this URL as an attachment.
When I click the Like button, the popup window (or “flyout”) doesn’t show. Why?
If the Like button is placed near the edge of an HTML element with the overflow property set to hidden, the flyout may be clipped or completely hidden when the button is clicked. This can be remedied by setting setting the overflow property to a value other than hidden, such as visible, scroll, or auto.