Sunday 27 March 2011

Facebook Perils


Dear fellow facebookers, do you by any chance have any idea how easy you make it for the cracker to crack your account? FYI, cracker is the bad guy, we hackers to ainveyi lut jaate hain.







Imagine, a roman gladiator, the greatest of his battalion, marches forward to fight with the enemy one on one. And suddenly, the villain politely asks, "Can you remove your chest guard please?"
And the gladiator does so, without even realizing that the villain can now easily strike him in the chest, and run thee spear right through his heart.!! Boy, that's brutal! :P

The same case happens with you people, sadly.
See, Mr. Zuckerberg is a highly reasonable man, and he fairly knows all the tricks of this hacking trade. So he has tried his level best to maintain and secure the privacy of hi users.
Infact, here's what Facebook has to say:


"Facebook does not allow users to track profile views or see statistics on how often a particular piece of content has been viewed and by whom. Third party developers, however, may offer apps that provide some of this functionality. Please keep a few things in mind when using these, however:

  1. Apps cannot track profile views for users who simply visit another person's profile. Facebook has made this technically impossible.
  2. In order to be tracked by an app, you must explicitly agree to allow the app to access your information.
  3. Adding an app that provides this functionality is purely optional. If you do not want to participate, please do not add the app to your account."
When the guy says security, he means it. But what can one do if the user specifically allows his/her privacy to become public? :P


See, let me explain it to you in a simple way, when you log into facebook, your username and password are sent to the facebook server, and the same information is stored in your own computer in special files called cookies.

And facebook does not allow users to track profile and applicaton views as in the case of orkut. So, if any application claims that with its help you can see your "stalkers", chances are that you may click on the link given (many of you do fall for it, face the truth dollface :P)
Now, there is a high possibility of a special type of attack known as Session Hijacking, in which the attacker steals your cookie data, i.e., your username and password, and needless to say, can use it to gain access to your account. Not so delicious, aren't you cookie? ;D

Look up session hijacking here, regards Wikipedia: en.wikipedia.org/wiki/Session_hijacking

Don't worry, there is not a total threat. The only way you can be safe from these type of attacks is that you ignore all those pestering links, even if they are sent to you by your closest friends.
Better safe than sorry. :-|

And let the goddamned stalkers visit your profile yaar, what can they possibly do? Tennu ki fark painda hai?

Take a chill pill, relax..and until next time….Happy Hacking J

1 comment: