<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: New Facebook Photo Hacks</title>
	<atom:link href="http://www.lightbluetouchpaper.org/2009/02/11/new-facebook-photo-hacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lightbluetouchpaper.org/2009/02/11/new-facebook-photo-hacks/</link>
	<description>Security Research, Computer Laboratory, University of Cambridge</description>
	<pubDate>Tue, 16 Mar 2010 20:11:40 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Arkhonx</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/11/new-facebook-photo-hacks/comment-page-1/#comment-50455</link>
		<dc:creator>Arkhonx</dc:creator>
		<pubDate>Wed, 03 Mar 2010 19:57:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=671#comment-50455</guid>
		<description>Is it possible to use this method to retrieve a recently deleted photo? The album's open and stuff. I basically have everything but the pin and the server. They seem to be different from picture to picture although they're in the same album.

Thanks in advance!</description>
		<content:encoded><![CDATA[<p>Is it possible to use this method to retrieve a recently deleted photo? The album&#8217;s open and stuff. I basically have everything but the pin and the server. They seem to be different from picture to picture although they&#8217;re in the same album.</p>
<p>Thanks in advance!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anonymous17</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/11/new-facebook-photo-hacks/comment-page-1/#comment-46407</link>
		<dc:creator>anonymous17</dc:creator>
		<pubDate>Fri, 29 Jan 2010 04:21:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=671#comment-46407</guid>
		<description>too bad ugly51 that seems like a virus not any kind of photo hosting on the part of facebook.
a quick google for zwunzi will tell.</description>
		<content:encoded><![CDATA[<p>too bad ugly51 that seems like a virus not any kind of photo hosting on the part of facebook.<br />
a quick google for zwunzi will tell.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ugly51</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/11/new-facebook-photo-hacks/comment-page-1/#comment-45899</link>
		<dc:creator>Ugly51</dc:creator>
		<pubDate>Sun, 24 Jan 2010 01:22:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=671#comment-45899</guid>
		<description>Reference the post regarding the link:

http://photos-a.ak.fbcdn.net/photos-ak-[anything]/

I was in the middle of experimenting with this URL, when my connection dropped out while the page was loading, leaving me with something quite interesting in my address bar.  I had:

http://www.zwunzi.com/[and a huge random sting]

I think this may be of interest.  Are Facebook hosting phots on Zwunzi.com?

The Zwunzi URL is not in my browser history, almost as though it never happened. Otherwise I would have posted the actual link here.</description>
		<content:encoded><![CDATA[<p>Reference the post regarding the link:</p>
<p><a href="http://photos-a.ak.fbcdn.net/photos-ak-anything/" rel="nofollow">http://photos-a.ak.fbcdn.net/photos-ak-anything/</a></p>
<p>I was in the middle of experimenting with this URL, when my connection dropped out while the page was loading, leaving me with something quite interesting in my address bar.  I had:</p>
<p><a href="http://www.zwunzi.com/and" rel="nofollow">http://www.zwunzi.com/and</a> a huge random sting]</p>
<p>I think this may be of interest.  Are Facebook hosting phots on Zwunzi.com?</p>
<p>The Zwunzi URL is not in my browser history, almost as though it never happened. Otherwise I would have posted the actual link here.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bridget</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/11/new-facebook-photo-hacks/comment-page-1/#comment-43344</link>
		<dc:creator>Bridget</dc:creator>
		<pubDate>Wed, 30 Dec 2009 22:31:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=671#comment-43344</guid>
		<description>For the fbcdngen script, how large is the text file supposed to be when you run with the old 4-digit pins?  I had to stop mine because it was approaching 400 gigabytes (after I left the computer for a few hours) and was going to fill up my entire hard drive if I let it run much longer. I don't know if it was looping infinitely or if those really are all individual values -- if the latter, how does anyone have the hard drive space for the 7-digit pins..?</description>
		<content:encoded><![CDATA[<p>For the fbcdngen script, how large is the text file supposed to be when you run with the old 4-digit pins?  I had to stop mine because it was approaching 400 gigabytes (after I left the computer for a few hours) and was going to fill up my entire hard drive if I let it run much longer. I don&#8217;t know if it was looping infinitely or if those really are all individual values &#8212; if the latter, how does anyone have the hard drive space for the 7-digit pins..?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jat</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/11/new-facebook-photo-hacks/comment-page-1/#comment-42942</link>
		<dc:creator>Jat</dc:creator>
		<pubDate>Sun, 27 Dec 2009 01:44:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=671#comment-42942</guid>
		<description>This doesn't work anymore does it? =[</description>
		<content:encoded><![CDATA[<p>This doesn&#8217;t work anymore does it? =[</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rohan Tarun</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/11/new-facebook-photo-hacks/comment-page-1/#comment-40486</link>
		<dc:creator>Rohan Tarun</dc:creator>
		<pubDate>Fri, 04 Dec 2009 03:07:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=671#comment-40486</guid>
		<description>I believe the script needs to be updated... as for there for the digits have been increased and extra numbers have been included...

please kindly lend us the updated version</description>
		<content:encoded><![CDATA[<p>I believe the script needs to be updated&#8230; as for there for the digits have been increased and extra numbers have been included&#8230;</p>
<p>please kindly lend us the updated version</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sasha</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/11/new-facebook-photo-hacks/comment-page-1/#comment-37542</link>
		<dc:creator>Sasha</dc:creator>
		<pubDate>Mon, 09 Nov 2009 17:27:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=671#comment-37542</guid>
		<description>Is there a way to figure out the sequence of the pin? For example, one of my pins (as you identify it) is .1273. 

If someone has that pin along with the [photo-size][uid]_[pid]_[pin], can they now view my other photos? Thanks!</description>
		<content:encoded><![CDATA[<p>Is there a way to figure out the sequence of the pin? For example, one of my pins (as you identify it) is .1273. </p>
<p>If someone has that pin along with the [photo-size][uid]_[pid]_[pin], can they now view my other photos? Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Interweb Troll</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/11/new-facebook-photo-hacks/comment-page-1/#comment-33525</link>
		<dc:creator>Interweb Troll</dc:creator>
		<pubDate>Tue, 08 Sep 2009 04:36:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=671#comment-33525</guid>
		<description>Hey, could you figure out who uploaded the photo which has a filename ending in 13523613_3602037.jpg? I think it's from an album, not a profile picture, hence it has a 5-string ID but I was only given two of the strings. I don't know the user ID of the person (that's what I'm trying to figure out). Any advice would be appreciated. Thanks.</description>
		<content:encoded><![CDATA[<p>Hey, could you figure out who uploaded the photo which has a filename ending in 13523613_3602037.jpg? I think it&#8217;s from an album, not a profile picture, hence it has a 5-string ID but I was only given two of the strings. I don&#8217;t know the user ID of the person (that&#8217;s what I&#8217;m trying to figure out). Any advice would be appreciated. Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anthony</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/11/new-facebook-photo-hacks/comment-page-1/#comment-33455</link>
		<dc:creator>Anthony</dc:creator>
		<pubDate>Sun, 06 Sep 2009 16:19:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=671#comment-33455</guid>
		<description>I don't care how long the PIN is; it's still technically a security issue. If they're using a 3rd party CDN with no intelligence aside from wget, that means that a "friend" can grab the true URL of a photo, post it somewhere, and that's that.

People are all caught up on the idea that a photo is secure, even on a CDN, as long as the URL is "unguessable". But isn't anyone concerned about an unguessable URL being acquired legitimately, but then posted somewhere it shouldn't be, at which point there is no ACL to check permissions?</description>
		<content:encoded><![CDATA[<p>I don&#8217;t care how long the PIN is; it&#8217;s still technically a security issue. If they&#8217;re using a 3rd party CDN with no intelligence aside from wget, that means that a &#8220;friend&#8221; can grab the true URL of a photo, post it somewhere, and that&#8217;s that.</p>
<p>People are all caught up on the idea that a photo is secure, even on a CDN, as long as the URL is &#8220;unguessable&#8221;. But isn&#8217;t anyone concerned about an unguessable URL being acquired legitimately, but then posted somewhere it shouldn&#8217;t be, at which point there is no ACL to check permissions?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: giraa2</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/11/new-facebook-photo-hacks/comment-page-1/#comment-33347</link>
		<dc:creator>giraa2</dc:creator>
		<pubDate>Fri, 04 Sep 2009 04:54:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=671#comment-33347</guid>
		<description>There is a proven method available for accessing photos from private profiles, it is described in:

http://privacystalker.blogspot.com/

It uses brute force attack approach! It works for me!!
It was written in spanish but you can always use google translator or babylon...</description>
		<content:encoded><![CDATA[<p>There is a proven method available for accessing photos from private profiles, it is described in:</p>
<p><a href="http://privacystalker.blogspot.com/" rel="nofollow">http://privacystalker.blogspot.com/</a></p>
<p>It uses brute force attack approach! It works for me!!<br />
It was written in spanish but you can always use google translator or babylon&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
