February 22, 2013 | perivision | Leave a comment Well, this not good for facebook. Your worried about your privacy? Try to use all the tools to protect yourself that facebook provides? May not matter. Check this out below. In Nir Goldshlager‘ post, he outlines, almost step by step, how you can perform the same ‘hack’. Facebook claims to have fixed this, but Nir says there are others and he will post them soon. I decided to share one of my favorite flaws i discovered in facebook.com, This flaw allowed me to take a full control over any Facebook account,By exploiting this flaw I could steal unique access tokens that provides me full control over any Facebook account, just to clarify there is no need for any installed apps on the victim’s account, Even if the victim never allowed any application in his Facebook account, I could still be getting full permissions (This bug works on any browser) To make this exploit work, The victim only need to visit a webpage, So OAuth is used by Facebook to communicate between Applications and Facebook users, Usally users must allow/accept the application request to access their account before the communication can start. Any Facebook application might ask for different permissions, For example: Diamond Dash,Texas Holdem Poker only have permission to basic information and post on user’s wall, I found a way in to get a full permissions (read inbox, outbox, manage pages, manage ads, read private photos, videos,etc..) over the victim account even without any installed apps on the victim’s account, Another advantage in the flaw I found is that there is no “Expired date” of the Token like there would be on any other application usage, In my attack the token never expires unless the victim change his password :), Share and Enjoy !Shares