<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mbotee&#039;s Blog &#187; Facebook</title>
	<atom:link href="http://www.mbotee.com/tag/facebook/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mbotee.com</link>
	<description>Fully Information Blog: About Computers, Business, SEO &#38; Blogging</description>
	<lastBuildDate>Thu, 09 Feb 2012 09:19:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>T.G.I. Friday’s Fans</title>
		<link>http://www.mbotee.com/2009/09/t-g-i-fridays-fans/</link>
		<comments>http://www.mbotee.com/2009/09/t-g-i-fridays-fans/#comments</comments>
		<pubDate>Tue, 22 Sep 2009 17:58:57 +0000</pubDate>
		<dc:creator>mbotee</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Intermezzo]]></category>
		<category><![CDATA[Burger]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Food]]></category>
		<category><![CDATA[Free]]></category>
		<category><![CDATA[Restaurants]]></category>
		<category><![CDATA[T.G.I. Friday's]]></category>
		<category><![CDATA[Woody]]></category>

		<guid isPermaLink="false">http://www.mbotee.com/?p=1054</guid>
		<description><![CDATA[T.G.I. Friday’s Fans T.G.I. Friday&#8217;s fast food restaurants introduce its self proclaimed #1 fan, &#8220;Woody&#8221;. And Woody here has special occasion called Thank God It&#8217;s Friday&#8217;s attitude. Woody loves to make life’s a party. Woody just loves everything about T.G.I. Friday’s; especially their signature Jack Daniel&#8217;s Grill and the Jack Daniel&#8217;s Burgers and Jack Daniel&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<h1 style="margin-bottom: 0cm; text-align: center;"><span style="color: #00ccff;"><strong>T.G.I. Friday’s  Fans</strong></span></h1>
<p><span style="color: #00ccff;"><strong><br />
</strong></span></p>
<p><object id="prnplayer" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="494" height="247" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowScriptAcess" value="sameDomain" /><param name="allowFullScreen" value="true" /><param name="quality" value="high" /><param name="wmode" value="transparent" /><param name="flashvars" value="titlefont=Arial,sans-serif&amp;titlecolor=ffffff&amp;playlistpath=tgifridays/tgifridayssocialmedianewsrelease-woody-jackdaniels&amp;job=39719" /><param name="src" value="http://www.prnewswire.com/container/players/200908/player.swf?job=39719" /><param name="name" value="player" /><param name="allowfullscreen" value="true" /><embed id="prnplayer" type="application/x-shockwave-flash" width="494" height="247" src="http://www.prnewswire.com/container/players/200908/player.swf?job=39719" name="player" flashvars="titlefont=Arial,sans-serif&amp;titlecolor=ffffff&amp;playlistpath=tgifridays/tgifridayssocialmedianewsrelease-woody-jackdaniels&amp;job=39719" wmode="transparent" quality="high" allowfullscreen="true" allowscriptacess="sameDomain"></embed></object></p>
<h3 style="text-align: justify;"><span style="color: #ffffff;">T.G.I. Friday&#8217;s fast food restaurants introduce its self proclaimed #1 fan, &#8220;Woody&#8221;. And Woody here has special occasion called Thank God It&#8217;s Friday&#8217;s attitude. Woody loves to make life’s a party. Woody just loves everything about T.G.I. Friday’s; especially their signature Jack Daniel&#8217;s Grill and the Jack Daniel&#8217;s Burgers and Jack Daniel&#8217;s Chicken Sandwiches. Woody always orders this every time he goes to T.G.I. Friday. Woody decided to do something funny about this restaurant based on his favorite to T.G.I. Friday restaurant.</span></h3>
<p><span style="color: #ffffff;"><span id="more-1054"></span><br />
</span></p>
<h3 style="text-align: justify;"><span style="color: #ffffff;">And <a href="http://www.prnewswire.com/container/tgifridays/tgifridayssocialmedianewsrelease-woody-jackdaniels/" target="_blank">Woody</a> had this crazy idea that he turned into a friendly bet: if he gets half a million Facebook fans by September 30, 2009, Friday&#8217;s will give away either a Jack Daniel&#8217;s Burger or Jack Daniel&#8217;s Chicken Sandwich to his first 500,000 fans. Sounds good isn’t. So if you want to get the famous <a href="http://www.prnewswire.com/container/tgifridays/tgifridayssocialmedianewsrelease-woody-jackdaniels/" target="_blank">T.G.I. Friday’s</a> Jack Daniel&#8217;s Burger or Jack Daniel&#8217;s Chicken Sandwich for free, then well go ahead and join as Woody’s fan on his <a href="http://www.prnewswire.com/container/tgifridays/tgifridayssocialmedianewsrelease-woody-jackdaniels/" target="_blank">Facebook</a> page. So will you join as his fan and help Woody to win his bet, and give you a free Burger or Sandwich. Join to Woody’s Facebook page as his fans to help him will this friendly bet.</span></h3>
]]></content:encoded>
			<wfw:commentRss>http://www.mbotee.com/2009/09/t-g-i-fridays-fans/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Facebook Hacking</title>
		<link>http://www.mbotee.com/2009/06/facebook-hacking/</link>
		<comments>http://www.mbotee.com/2009/06/facebook-hacking/#comments</comments>
		<pubDate>Fri, 19 Jun 2009 23:28:27 +0000</pubDate>
		<dc:creator>mbotee</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Facebook]]></category>

		<guid isPermaLink="false">http://www.mbotee.com/?p=252</guid>
		<description><![CDATA[Facebook Hacking: View Everyones Photos We’ve all done it. We’ve all accidentally use Social Networking websites to spy on other people and/or collecting photos of real cute girls! You start surfing on the Internet with the best intentions, but somehow you end up in one of those want-to-know-even-I’m-dying curious state and wake up done collecting [...]]]></description>
			<content:encoded><![CDATA[<h1 style="text-align: center;"><span style="color: #00ccff;">Facebook Hacking: View Everyones Photos</span></h1>
<h3><span style="color: #ffffff;"><span style="color: #000000;">We’ve all done it. We’ve all accidentally use </span><a href="http://en.wikipedia.org/wiki/List_of_social_networking_websites"><span style="color: #000000;">Social Networking websites</span></a><span style="color: #000000;"> to spy on other people and/or collecting photos of real cute girls! You start surfing on the Internet with the best intentions, but somehow you end up in one of those want-to-know-even-I’m-dying curious state and wake up done collecting information and photos like a digital </span><a href="http://en.wikipedia.org/wiki/Stalker"><span style="color: #000000;">stalker</span></a><span style="color: #000000;">. Doing all this kind of things is almost a rite of passage for computer-freak male. There’s no shame in that.</span></span></h3>
<h3><span style="color: #000000;">This is being said, very few of us have done stalking and stealing information about cute girls for the sake of nothing. There must be something behind it: you want to keep an eye on your girlfriend or wife (that means you’re one of a hell possessive guy), wanted to do information gathering on your new date (that means you’re immature) or even just love to collect pretty girl’s photos for your own needs (that means you’re either a freak, stalker, or an Anti-social). I will be honest. I maybe a member of those clubs, but it’s up for debate. Let me explain:</span></h3>
<h3><span style="color: #ffffff;"><span id="more-341"><span style="color: #000000;"> </span></span></span></h3>
<h3><span style="color: #ffffff;"><span style="color: #000000;">It was started a few days ago, when </span><strong><span style="color: #000000;">Whindy Yoevestian</span></strong><span style="color: #000000;"> (as my book’s editor) told me that </span><a href="http://www.facebook.com/"><span style="color: #000000;">FaceBook</span></a><span style="color: #000000;"> is indeed one of the most selling book topics in Indonesia through the phone while my girlfriend was busy playing with her </span><a href="http://www.blackberry.com/"><span style="color: #000000;">BlackBerry</span></a><span style="color: #000000;"> opening FaceBook and do gossips there! LoL! I feel lost &#8211; it was really like, I’m in the middle of nowhere and I don’t know a thing about FaceBook which everybody always talked about! So, I decided to get my move!</span></span></h3>
<h3><span style="color: #000000;">Register myself for FaceBook, add several people, do a little surfing inside &#8211; looking for any good applications and games to play with, I found the fact that I may use this FaceBook to see my ex-girlfriend’s photos! I wonder how is she looks like now (really, just wondering). I searched for her name by using the search box located on the top-right side of the FaceBook home index page and I found her &#8211; it was no more than 3 seconds.</span></h3>
<h3><span style="color: #ffffff;"><span style="color: #000000;">Damn! I cannot have my eyes on her photos, it’s because FaceBook is not allowing me to see any of her profile information and/or photos when I’m not within her friend list. Now, I’m getting bored! Accidentally, I’ve got a friend of mine whose telling me to give her comments on her brand new Album in FaceBook! She gave me the URL to her Album &#8211; and the URL look .<br />
</span> </span></h3>
<p><span id="more-252"></span></p>
<h3 style="text-align: justify;"><span style="color: #000000;">just like this:</span></h3>
<h3><span style="color: #ffffff;"><em><span style="color: #000000;">http://www.facebook.com/album.php?aid=</span><strong><span style="color: #000000;">161512</span></strong><span style="color: #000000;">&amp;id=</span><strong><span style="color: #000000;">987654321</span></strong></em></span></h3>
<h3><span style="color: #ffffff;"><span style="color: #000000;">Hey wait a moment, isn’t that means I can do something since people can easily see other user’s ID when they can search them through the search column? I tried to get my ex-girlfriend’s profile again by search and find out that when you clicked the </span><em><span style="color: #000000;">“View Friends”</span></em></span><span style="color: #000000;"> link, FaceBook will appoint me to this URL:</span></h3>
<h3><span style="color: #ffffff;"><em><span style="color: #000000;">http://www.facebook.com/friends/?id=</span><strong><span style="color: #000000;">123456789</span></strong></em></span></h3>
<h3><span style="color: #ffffff;"><span style="color: #000000;">Then I noticed that the id= variable might be the key to someone’s individual profile numbers. I tried to put my friend’s ID (which actually was 987654321) to the </span><em><span style="color: #000000;">“View Friends”</span></em></span><span style="color: #000000;"> URL format and press my enter button! Bingo! I saw my friend’s friends now! That means this id= variable is the ID for every user’s profile number. But wait! What is aid= variable used for? Again, I surfed for quite some times and I found that aid= variable is something like 5 or 6 random numbers.</span></h3>
<h3><span style="color: #ffffff;"><span style="color: #000000;">Hmm, looks tough, I think of only a bruteforce attack! I won’t bruteforce their passwords or anything (since I do not even know the emails they are using to logged in), but I will bruteforce the URL instead! Yup! Imagine that your victim id= variable is 981676553 but you know nothing about his/her aid= variable, isn’t it always easy to use a software which can try URLs from </span><em><span style="color: #000000;">http://www.facebook.com/album.php?aid=00000&amp;id=981676553</span></em><span style="color: #000000;"> to </span><em><span style="color: #000000;">http://www.facebook.com/album.php?aid=999999&amp;id=981676553</span></em><span style="color: #000000;"> and determine which one is a valid link and which are not? Hehehe! In this case, I pick </span><a href="http://www.owasp.org/index.php/Category:OWASP_Webslayer_Project"><span style="color: #000000;">WebSlayer</span></a><span style="color: #000000;"> as my most favorite tools to do the job!</span></span></h3>
<h3><span style="color: #ffffff;"><span style="color: #000000;">Just download it </span><a href="http://code.google.com/p/webslayer/downloads/list"><span style="color: #000000;">here</span></a><span style="color: #000000;">!</span></span></h3>
<h3><span style="color: #ffffff;"><span style="color: #000000;">Now as I opened my WebSlayer application I’m being faced to the Attack Setup tab page where I need to fill information about my targeted website &#8211; I put </span><strong><em><span style="color: #000000;">http://www.facebook.com/FUZZ</span></em></strong><span style="color: #000000;"> as the victimized URL (the word FUZZ is kind of a command for the application that says those part are the one to be bruteforced):</span></span></h3>
<h3 style="text-align: center;"><span style="color: #ffffff;"><a href="http://img14.imageshack.us/img14/9394/brutezyv.jpg" target="_blank"><img class="aligncenter" src="http://img14.imageshack.us/img14/9394/brutezyv.jpg" alt="The Attack Settings!" width="429" height="300" /></a></span></h3>
<h3><span style="color: #000000;">What did I do next is to set my pattern of Fuzzing (guessing) from the Payload Generator &#8211; I really love to use the Range one, although file and permutation type are also good! I put the range, the pattern and generate it! When you done all those things, you should be able to see the exactly same looks as this picture:</span></h3>
<h3 style="text-align: center;"><span style="color: #ffffff;"><a href="http://img14.imageshack.us/img14/6937/brutez.jpg" target="_blank"><img class="aligncenter" src="http://img14.imageshack.us/img14/6937/brutez.jpg" alt="The Payload Settings!" width="429" height="300" /></a></span></h3>
<h3><span style="color: #ffffff;"><span style="color: #000000;">Then go back to the </span><em><span style="color: #000000;">Attack Setup</span></em><span style="color: #000000;"> tab, select Payload as your Payload type, import the Fuzz from Generator and click on the </span><em><span style="color: #000000;">“Start Attack”</span></em><span style="color: #000000;"> button! What will you see next is this kind of a picture:</span></span></h3>
<h3 style="text-align: center;"><span style="color: #ffffff;"><a href="http://img14.imageshack.us/img14/8194/brutew.jpg" target="_blank"><img class="aligncenter" src="http://img14.imageshack.us/img14/8194/brutew.jpg" alt="The Attack Started!" width="429" height="300" /></a></span></h3>
<h3><span style="color: #000000;">Look at the bruteforced URLs up there! The one highlighted with light-brown colors are the valid links! Try opening those URLs and you’ll be able to see my friend’s albums (2 of them) but when you try the non-Highlighted URLs &#8211; you’ll found that those contents are not available at the moment (FaceBook will say that). Hehehe!</span></h3>
<h3><span style="color: #000000;">I use it on my ex-girlfriend’s profile while doing more research on it (plus reading from other people’s information too), I found out that there were tons of easier ways to do it, better accuracy and faster results! So I tried to make myself through those ways and viola, I was able to view all my ex-girlfriend’s photos within no more than 3 minutes of waiting! Hehehe!</span></h3>
<h3><span style="color: #ffffff;"><strong><span style="color: #000000;">NB:</span></strong><span style="color: #000000;"> </span><em><span style="color: #000000;">I won’t tell you guys how to do the faster and easier way, but I will tell you, it’s not that hard and it’s real! If you want to know more about this kind of stuffs, please do it yourself before asking! I know you guys can do it! And if you’re about to ask me how to steal people’s account, believe me, phishing attack is still the best; especially when they’re being mixed with several XSS which are still left unfixed around FaceBook applications and PHP scripts.</span></em></span></h3>
<h3><span style="color: #ffffff;"><em><strong><span style="color: #000000;">Special thanks goes to Zealtous whose without his Windows operation system this article won’t be exist!</span></strong></em></span></h3>
<h4>Incoming search terms:</h4><ul><li><a href="http://www.mbotee.com/2009/06/facebook-hacking/" title="webslayer facebook">webslayer facebook</a></li><li><a href="http://www.mbotee.com/2009/06/facebook-hacking/" title="webslayer facebook 2011">webslayer facebook 2011</a></li><li><a href="http://www.mbotee.com/2009/06/facebook-hacking/" title="HOW TO USE WEBSLAYER">HOW TO USE WEBSLAYER</a></li><li><a href="http://www.mbotee.com/2009/06/facebook-hacking/" title="facebook webslayer">facebook webslayer</a></li><li><a href="http://www.mbotee.com/2009/06/facebook-hacking/" title="webslayer facebook hack">webslayer facebook hack</a></li><li><a href="http://www.mbotee.com/2009/06/facebook-hacking/" title="webslayer facebook download">webslayer facebook download</a></li><li><a href="http://www.mbotee.com/2009/06/facebook-hacking/" title="hack facebook">hack facebook</a></li><li><a href="http://www.mbotee.com/2009/06/facebook-hacking/" title="webslayer hack">webslayer hack</a></li><li><a href="http://www.mbotee.com/2009/06/facebook-hacking/" title="webslayer fuzz">webslayer fuzz</a></li><li><a href="http://www.mbotee.com/2009/06/facebook-hacking/" title="webslayer facebook photo">webslayer facebook photo</a></li></ul><!-- SEO SearchTerms Tagging 2 plugin took 2.167 ms -->]]></content:encoded>
			<wfw:commentRss>http://www.mbotee.com/2009/06/facebook-hacking/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

