Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[WARN] Think twice before use token sites #2

Open
kowith337 opened this issue Oct 13, 2018 · 0 comments
Open

[WARN] Think twice before use token sites #2

kowith337 opened this issue Oct 13, 2018 · 0 comments

Comments

@kowith337
Copy link
Owner

See the new function to generate token due to old method (use app token from phone manufactor like HTC, Blackberry, Samsung, etc.) are now deprecated.

The new method is use Facebook App API (Android/iOS) to generate token, however.

GENERATING TOKEN FROM THOSE SCAM SITES WILL EXPOSE YOUR FULL USERNAME AND PASSWORD TO SITE OWNER!

DON'T TRUST THE SITE EVEN THE SITE SAID THEY NOT SAVE USERNAME AND PASSWORD IN THEIR SERVER, IN FACT, THEY CAN DEFINITELY DO!!

image

Timestamp Domain Switch Type URL Party
23:48:27 www.n-like.com   css https://api.facebook.com/restserver.php?api_key=882a8490361da98702bf97a021ddc14d&credentials_type=password&email=example@example.com&format=JSON&method=auth.login&password=example&v=1.0&sig=28879c0ff89fc2aeb718cee7d0a011f1{inline_style} 3p
23:48:24 www.n-like.com   frame https://api.facebook.com/restserver.php?api_key=882a8490361da98702bf97a021ddc14d&credentials_type=password&email=example@example.com&format=JSON&method=auth.login&password=example&v=1.0&sig=28879c0ff89fc2aeb718cee7d0a011f1 3p
-- -- -- -- --
23:46:01 www.n-like.com   xhr https://logintoken.n-like.com/2.php
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant