Here's one theory and analysis of what might have happened. Some people's emails got out into the public internet, and were indexed. Some of these emails were from Facebook, and included links to resources that require login. These links pre-populated the username field for convenience, or in some cases auto-login the user. Facebook's engineers probably did not anticipate email notifications to users being crawled by…
More than 1MM Facebook accounts exposed
41–50 of 181 posts
Re: More than 1MM Facebook accounts exposed
#42What is the meaning of the square brackets in the Google query syntax? I could not find any official documentation.
https://www.google.com/search?q=inurl%3Abcode%3D*%2Bn_m%3D*+...
Re: More than 1MM Facebook accounts exposed
#43Here's one theory and analysis of what might have happened. Some people's emails got out into the public internet, and were indexed. Some of these emails were from Facebook, and included links to resources that require login. These links pre-populated the username field for convenience, or in some cases auto-login the user. Facebook's engineers probably did not anticipate email notifications to users being crawled by…
Doesn't Google's toolbar phone home with the URLs you click on? That could be a way to get supposedly-private URLs into Google's list of URLs to be visited.
Re: More than 1MM Facebook accounts exposed
#44Here's one theory and analysis of what might have happened. Some people's emails got out into the public internet, and were indexed. Some of these emails were from Facebook, and included links to resources that require login. These links pre-populated the username field for convenience, or in some cases auto-login the user. Facebook's engineers probably did not anticipate email notifications to users being crawled by…
yahoogrupos.com.br
yahoogroupes.fr
asdasd.ru
blogger.com
Seems like emails on these domains are much more easily viewable/leakable/indexable than normal personal email addresses?EDIT: Googling one of the discovered gmail address revealed a Facebook email (with 'bcode') being auto-blogged at weight-loss-information-123.blogspot.com https://encrypted.google.com/search?hl=en&q=danielsams20... - some kind of malware maybe?
Re: More than 1MM Facebook accounts exposed
#45Large number of login emails seem to be from asdasd.ru domain. Googling one of these emails I find a site that resembles a public inbox with emails from Facebook in it, like this one - http://asdasd.ru/read/414831 .
Re: More than 1MM Facebook accounts exposed
#46Here's one theory and analysis of what might have happened. Some people's emails got out into the public internet, and were indexed. Some of these emails were from Facebook, and included links to resources that require login. These links pre-populated the username field for convenience, or in some cases auto-login the user. Facebook's engineers probably did not anticipate email notifications to users being crawled by…
"Some people's emails got out into the public internet, and were indexed. Some of these emails were from Facebook, and included links..." Doesn't Google's toolbar phone home with the URLs you click on? That could be a way to get supposedly-private URLs into Google's list of URLs to be visited.
I think if it were google's toolbars picking up urls in emails, that there would be many more email domains here.
Re: More than 1MM Facebook accounts exposed
#47Re: More than 1MM Facebook accounts exposed
#48Facebook's privacy settings have a ton of bugs. Here's another one: 1. Make a stupid status update post. 2. It appears in all your friends newsfeed. 3. You realize you said something stupid and private. 4. Panic. Delete post 5. Breathe sigh of relief that it is no longer showing up in your profile. 6. But wait a minute! It still keeps showing up in all your friends newsfeed. 7. Now that you deleted the post, you can'…
Re: More than 1MM Facebook accounts exposed
#49What exactly was exposed here. It looks like it's been blocked now... Just stealing from other bit in this thread: somehow these urls got on the Internet even though they shouldn't have. They are pre-authed urls that auto-login and then expire.
Re: More than 1MM Facebook accounts exposed
#50I wonder if this is the source of the Facebook data leak ("I just bought more than 1 million Facebook data entries") last week?