Hacking Cardomain and Facebook


E-mail this post



Remember me (?)



All personal information that you provide here will be governed by the Privacy Policy of Blogger.com. More...



Yes I was bored. After farting around with cardomain for a little while, I found I could automaticlly post in guest books just by entering the correct address in the address bar. You ever see all those annoying "Nice ride, check mine out sometime!" posts people make, to try to get their votes up? well you can now be just as annoying! This isn't limited to Cardomain. I found you could use the same method to add thousands of Facebook friends in a matter of minutes. I'll explain at the end of this post

Here is a link for posting a guest book on cardomain
http://www.cardomain.com/guestbook/259001?sign=1&message=nice%20ride!

"259001" is the member number. I believe this is assigned based on when you signed up, so the next user who signed up would be 259002, and so on. "?sign=1" is necessary...just a random flag. "&message=" this is where your message is. Every space you use needs to be replaced by a "%20".

There is a 30 second time limit in posting, but I believe that's based on cookies, and writing a simple script will avoid that.

As I said, this isn't limited to cardomain. Hacking facebook works the same way. Do it yourself is as follows. First, go through the process of adding a friend. Find someone you are not currently friends with, and click "add". You need to go through the steps until clicking once more will add a friend ("are you sure you want to add this person?" -> yes -> "are you really sure?" -> yes "Are you really really really sure?" -> last step, so stop).
Next, you will notice the address is seomthing like
http://clemson.thefacebook.com/addfriend.php?id=12700907
Notice the ID is a number. If you adjust the number, you will start cycling through facebook members. Now here is the tricky part. You will need to "view source." Find the snippet of code that says "are you sure you want to add Ms Sorwhore as a friend?" Embedded in this question, you will find several input variables. This is where you start assembling your address. Every time you see a "name=", that is the variable name. "name=confirmed value=1" for instance. you add that to your address like so:

http://clemson.thefacebook.com/addfriend.php?id=12700907&confirmed=1

Note, each variable is seperated by a "&"
If you log into facebook and paste that address, you will invite a random person named Lindsay to be your friend. Webpages may have multiple variables, as in the cardomain example. Each time, you seperate the variable with "&". To invite thousands of people, just add 1 every time you past that address. 12700907, 12700908, 12700909, et cetera. This technique is applicable to almost any webpage where you can post. Next time you write a blog look at the address bar. You can even post to a blog by entering the correct address.

Just so everyone knows, after poking about 300 people on facebook, I got a 6 hour restriction where I couldn't send any more messages or pokes :)

And there you go, HTML injection 101.


    If the human body was never exposed to ailments, it would be impressivly vulnerable to the slightest cold. If our country was never exposed to hacking, it would be oppressivly vulnerable to cyber terrorism. With out the creation of a malicious hacking, Afganistan could have destroyed America's economy with a ping flood. This is why I encourange maclicious hacking, as an ethical practice. Without strengthening our defenses, we are weak. This site is focused on security through knowledge. I detest the fact that so many companies are being exploited because malicious hackers know their security holes before they do. For that reason, I hope to educate where the exploits lay. This isn't a 100% information base, as I only publish things I have been able to implement on myself. No credit is needed anywhere . However if you are a publisher, I would appriciate credit. I am an advocate of open source, so copy and paste and call it your own if you like. If my work is good enough for you to plagerize then that is my biggest compliment . If my work is good enough, I will be approached and asked to write more ... this is natural selection of the digital age .

Previous hacks

Previous Hacks



    This link kills spam


    spam IP addresses


    These are sites I block at my firewall.

    cdn2.gms1.net
    gms1.net
    servedby.advertising.com
    advertising.com
    a.tribalfusion.com
    tribalfusion.com
    pimpslord.com
    altfarm.mediaplex.com
    mediaplex.com
    ad.yeildmanager.com
    yeildmanager.com
    doubleclick.net
    isg32.casalemedia.com
    casalemedia.com

    Cost of the War in Iraq
    (JavaScript Error)

Two very recommended books:



. . The only hacking forum I have found worth mentioning here