Live data from Hacker News

More than 1MM Facebook accounts exposed

google.com

1–10 of 181 posts

Re: More than 1MM Facebook accounts exposed

#4

I don't understand how these pages could have been crawled - could someone enlighten?

It's seems that Facebook uses robots.txt to block this pages

https://www.facebook.com/robots.txt

But, depending of the amount of inbound links, Google will index the urls anyway.

It's a common issue.

Re: More than 1MM Facebook accounts exposed

#7
post #3

I don't see anything except results for "bcode"

When I click on a link I see another person's email address in the login box. I assume it's a facebook user's email.

See these two examples :

http://www.facebook.com/login.php?next=http%3A%2F%2Fwww.face...

http://www.facebook.com/login.php?next=http%3A%2F%2Fwww.face...

Re: More than 1MM Facebook accounts exposed

#8
Weird. I clicked on one of the links and it asked me if I was that user, and, if so, that I should click the login button. When I did, it logged me in as that user.

Edit: This happens for multiple users.

Edit2: It looks like if you click on the link, it automatically expires. bCODE is "an identifier that can be sent to a mobile phone/device and used as a ticket/voucher/identification or other type of token." I'm guessing somehow these tokens (the ones that auto log you in) never got used, plus the old ones were saved and contain email info. Not sure how Google could have gotten them though. Probably just got accidentally listed, despite robots.txt.

Re: More than 1MM Facebook accounts exposed

#10
post #7
post #3

I don't see anything except results for "bcode"

When I click on a link I see another person's email address in the login box. I assume it's a facebook user's email. See these two examples : http://www.facebook.com/login.php?next=http%3A%2F%2Fwww.face... http://www.facebook.com/login.php?next=http%3A%2F%2Fwww.face...

[deleted]
Post reply on HN