Skip to main content

Facebook comments Spam Bypass

Facebook comments doesn't allow you to post same comment all the type and this is the story how I bypassed this spam protection.
It was very hot afternoon and I was scrolling the news feed of my Facebook News Feed which is flooded by the posts of the actors and others. 

I was continuously posting the video URL of YouTube.
Actress and Other Facebook Pages  allow commenting. So when I was commenting the same URL on lot of posts including the actors.

Suddenly there was a pop up that was shown saying

You can't post at this time and it was going against our terms of service.

So I thought in my mind I need to bypass this.
I just posted another URL of the video. Now it allowed me to post !!!

What a surprise!! It allowed me to post a different URL.

I was curious to know why it happened and next I posted the previous URL that I was posting continuosly once again. Again there was an alert popup saying the same message about spam.

If you are aware about the Linkshim that facebook uses. 

If you click on any URL that is shared as a link on FB. then you may notice in the next tab that opens up something like this... https://l.facebook.com?redirect=<URL_you_wanted_to_visit>.

The use of of this linkshim is it will not allow you to visit evil websites.
So, i think you know what I will be doing next.

I used the linkshim URL of the video that was unable to post continuously.
and there I go . 

It worked!! 
I reported it to Facebook and they said and it wasn't a big issue because any one could use a redirect link to the Video's URL instead of linkshim.

Comments

Post a Comment

Popular posts from this blog

Google form setting Bypass - Making my way to the Google's Hall of Fame !

  G o o g l e ! Bug : Circumventing "Limit to 1 response" of  Google forms  ( Parameter Injection )        Discovered on: 30th, November 2016.            Research Time: 2:00 p.m to 9:30 p.m. Earn more by display ads on blog with  Lithific Ads The setting is "Limit to 1 response" which means only one response per user. Once you filled the form there will be no chance to edit the responses or again fill a new form. If you open the form to fill again, the response would be like the image below. There is no way to edit or fill another form (Hurdle 1). I created a test form and checked "Edit after submit". Once this test form is filled I can change the previous response.  I clicked on the "Edit your  response"and intercepted the request.  I changed the form id and forwarded the request. I was able to see the form that was submitted. When I edited the form and submitted, a blank form was sent. (Hurdle 2). I analysed the requests f

Facebook Bug Bounty $$$$ : Crossposting Live Videos | Facebook Live

In the Facebook Page Settings, you could setup the option for Crossposting Live videos from other pages.  The Attacker's page adds a Page (Victim's Page) for crossposting their videos Victim Page's Admin accepts the approval and the default option is Crossposting videos without further approval The Attacker starts live video and selects Victim's Page in the "Crosspost to more pages" Victim visits the Crossposting page in the Page settings and and removes Attacker's Page Attacker selects "Use camera" and clicks on "Go Live". The Victim's Page starts automatically crossposting the live video of Attacker,  Bug Bounty of $500

Facebook Messenger bug. React to any message on behalf of a Facebook Page

Reacting to Facebook Messages  An Admin can interact with his Facebook Page through Facebok page's Inbox, there is no UI to react to the messages like HAHA, LOVE etc.  Reply to the messages . You must be knowing about the WhatsApp messenger's Reply feature where you can reply to a particular message. There is something for Facebook messenger too. You can reply to message by hovering over the message and there will be "Reply" option. Click on that.  Now type some random message and click on "Send" and intercept the request. You can find in the HTTP Request that there is a parameter "message_id" in the message body. Change to some other message_id that doesn't belong to chat that you currently opened. Now I sent the request. There was an error that was thrown saying .. "The content is longer available".  Now my next adventure to try to find a bug in the Messaging continues. If you have a conversation with your girlfriend you can alway