SlideShare una empresa de Scribd logo
1 de 1
Intro to Facebook Stalking - Pictures
- Gaurav Ragtah


When someone sends you a facebook image URL (ie. just the image opens in the browser, and nothing else), it looks something
like this:

https://fbcdn-sphotos-a.akamaihd.net/hphotos-ak-snc6/216083_10150177890751234_515006233_6971227_4935405_n.jpg

(you can get an image URL by right clicking on an image in facebook and selecting 'copy image URL')

Now, notice the part of the URL after the last '/' :216083_10150177890751234_515006233_6971227_4935405_n.jpg

There are five numbers here.

The first, fourth and fifth are timestamp generated by facebook when one uploads an image.
The second and third numbers, however, are the picture id and the user profile id (person who uploaded the image)
respectively.

So to see the actual image in the album context, plug in the 2nd number into
https://www.facebook.com/photo.php?fbid=
which in our case will be
https://www.facebook.com/photo.php?fbid=10150177890751234


AND

to see the user profile of the person who uploaded the picture, plug in the 3rd number from the image URL into
https://www.facebook.com/profile.php?id=
which in our case will be
https://www.facebook.com/profile.php?id=515006233


VOILA!! ;)

Happy facebook-ing.


Read on:

Now, a bruteforce script can be easily written to generate timestamps to plug-in for the Image URLs so that you can possibly view
and download private images from someone's profile that you cannot view directly through facebook. (There is literature on the
web about that, about how to do it and how it's easier to bruteforce for timestamps than for truly randomly generated numbers
which facebook did not implement)

Some facebook pictures that you upload and later delete/ set to private still exist on facebook's 3rd party servers and can still be
viewed by the image URL links; further, they can be traced down to who uploaded them.
As a test, I uploaded an image, took note of its image URL and then deleted it from facebook. The image is still out
there in the image hosting servers as you can see here:

https://fbcdn-sphotos-a.akamaihd.net/hphotos-ak-ash4/321248_10150325810871234_515006233_8188580_1724070261_n.jpg


So, as a general rule, don't upload stuff you wouldn't be very uncomfortable with if made public.


- Gaurav




Note: This doesn't work for images uploaded prior to late 2009 or so, I think, since Facebook slightly changed the way the images
were organized on their storage servers.

Más contenido relacionado

La actualidad más candente

Beyond Data: Building a Web of Needs
Beyond Data: Building a Web of NeedsBeyond Data: Building a Web of Needs
Beyond Data: Building a Web of Needs
fkleedorfer
 

La actualidad más candente (20)

Mc leod jamal_finalslideshow
Mc leod jamal_finalslideshowMc leod jamal_finalslideshow
Mc leod jamal_finalslideshow
 
Cybersecurity - NSA Style
Cybersecurity - NSA StyleCybersecurity - NSA Style
Cybersecurity - NSA Style
 
Why You Need An Agenda For Every Meeting
Why You Need An Agenda For Every MeetingWhy You Need An Agenda For Every Meeting
Why You Need An Agenda For Every Meeting
 
Interview Mastery - Satoshi Takano, Humber College
Interview Mastery - Satoshi Takano, Humber CollegeInterview Mastery - Satoshi Takano, Humber College
Interview Mastery - Satoshi Takano, Humber College
 
5 Fails for Facebook Insights
5 Fails for Facebook Insights5 Fails for Facebook Insights
5 Fails for Facebook Insights
 
Resume Writing Mastery - Humber College
Resume Writing Mastery - Humber CollegeResume Writing Mastery - Humber College
Resume Writing Mastery - Humber College
 
How to Twitter
How to TwitterHow to Twitter
How to Twitter
 
Applying to Doctoral Programs: Crafting the Letter of Intent and Academic CV
Applying to Doctoral Programs: Crafting the Letter of Intent and Academic CVApplying to Doctoral Programs: Crafting the Letter of Intent and Academic CV
Applying to Doctoral Programs: Crafting the Letter of Intent and Academic CV
 
Beyond Data: Building a Web of Needs
Beyond Data: Building a Web of NeedsBeyond Data: Building a Web of Needs
Beyond Data: Building a Web of Needs
 
Fresh Lemona.de
Fresh Lemona.deFresh Lemona.de
Fresh Lemona.de
 
SlideShare for your Personal and Company Brand
SlideShare for your Personal and Company Brand SlideShare for your Personal and Company Brand
SlideShare for your Personal and Company Brand
 
How to Increase Your Influence at Work - An HBR Article Feb 2018
How to Increase Your Influence at Work - An HBR Article Feb 2018How to Increase Your Influence at Work - An HBR Article Feb 2018
How to Increase Your Influence at Work - An HBR Article Feb 2018
 
Employee Enablement on Social - Brand Advocates for Influence - Best Practices
Employee Enablement on Social - Brand Advocates for Influence - Best PracticesEmployee Enablement on Social - Brand Advocates for Influence - Best Practices
Employee Enablement on Social - Brand Advocates for Influence - Best Practices
 
Michael Fraser Leicestershire and Rutland Chess Association
Michael Fraser Leicestershire and Rutland Chess AssociationMichael Fraser Leicestershire and Rutland Chess Association
Michael Fraser Leicestershire and Rutland Chess Association
 
Employer Branding: Do you Know the Origins?
Employer Branding: Do you Know the Origins?Employer Branding: Do you Know the Origins?
Employer Branding: Do you Know the Origins?
 
Fokus - smarter analytics na Aula Polska Poznań
Fokus - smarter analytics na Aula Polska Poznań Fokus - smarter analytics na Aula Polska Poznań
Fokus - smarter analytics na Aula Polska Poznań
 
Applying to Doctoral Programs: Discussing the Decision With Others
Applying to Doctoral Programs: Discussing the Decision With OthersApplying to Doctoral Programs: Discussing the Decision With Others
Applying to Doctoral Programs: Discussing the Decision With Others
 
Stressless Paperless
Stressless PaperlessStressless Paperless
Stressless Paperless
 
Applying to Doctoral Programs: Reference Letters
Applying to Doctoral Programs: Reference LettersApplying to Doctoral Programs: Reference Letters
Applying to Doctoral Programs: Reference Letters
 
Twitter for Beginners
Twitter for BeginnersTwitter for Beginners
Twitter for Beginners
 

Último

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 

Último (20)

Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 

Facebook Geek Tricks - Pictures

  • 1. Intro to Facebook Stalking - Pictures - Gaurav Ragtah When someone sends you a facebook image URL (ie. just the image opens in the browser, and nothing else), it looks something like this: https://fbcdn-sphotos-a.akamaihd.net/hphotos-ak-snc6/216083_10150177890751234_515006233_6971227_4935405_n.jpg (you can get an image URL by right clicking on an image in facebook and selecting 'copy image URL') Now, notice the part of the URL after the last '/' :216083_10150177890751234_515006233_6971227_4935405_n.jpg There are five numbers here. The first, fourth and fifth are timestamp generated by facebook when one uploads an image. The second and third numbers, however, are the picture id and the user profile id (person who uploaded the image) respectively. So to see the actual image in the album context, plug in the 2nd number into https://www.facebook.com/photo.php?fbid= which in our case will be https://www.facebook.com/photo.php?fbid=10150177890751234 AND to see the user profile of the person who uploaded the picture, plug in the 3rd number from the image URL into https://www.facebook.com/profile.php?id= which in our case will be https://www.facebook.com/profile.php?id=515006233 VOILA!! ;) Happy facebook-ing. Read on: Now, a bruteforce script can be easily written to generate timestamps to plug-in for the Image URLs so that you can possibly view and download private images from someone's profile that you cannot view directly through facebook. (There is literature on the web about that, about how to do it and how it's easier to bruteforce for timestamps than for truly randomly generated numbers which facebook did not implement) Some facebook pictures that you upload and later delete/ set to private still exist on facebook's 3rd party servers and can still be viewed by the image URL links; further, they can be traced down to who uploaded them. As a test, I uploaded an image, took note of its image URL and then deleted it from facebook. The image is still out there in the image hosting servers as you can see here: https://fbcdn-sphotos-a.akamaihd.net/hphotos-ak-ash4/321248_10150325810871234_515006233_8188580_1724070261_n.jpg So, as a general rule, don't upload stuff you wouldn't be very uncomfortable with if made public. - Gaurav Note: This doesn't work for images uploaded prior to late 2009 or so, I think, since Facebook slightly changed the way the images were organized on their storage servers.