SlideShare uma empresa Scribd logo
1 de 1
Intro to Facebook Stalking - Pictures
- Gaurav Ragtah


When someone sends you a facebook image URL (ie. just the image opens in the browser, and nothing else), it looks something
like this:

https://fbcdn-sphotos-a.akamaihd.net/hphotos-ak-snc6/216083_10150177890751234_515006233_6971227_4935405_n.jpg

(you can get an image URL by right clicking on an image in facebook and selecting 'copy image URL')

Now, notice the part of the URL after the last '/' :216083_10150177890751234_515006233_6971227_4935405_n.jpg

There are five numbers here.

The first, fourth and fifth are timestamp generated by facebook when one uploads an image.
The second and third numbers, however, are the picture id and the user profile id (person who uploaded the image)
respectively.

So to see the actual image in the album context, plug in the 2nd number into
https://www.facebook.com/photo.php?fbid=
which in our case will be
https://www.facebook.com/photo.php?fbid=10150177890751234


AND

to see the user profile of the person who uploaded the picture, plug in the 3rd number from the image URL into
https://www.facebook.com/profile.php?id=
which in our case will be
https://www.facebook.com/profile.php?id=515006233


VOILA!! ;)

Happy facebook-ing.


Read on:

Now, a bruteforce script can be easily written to generate timestamps to plug-in for the Image URLs so that you can possibly view
and download private images from someone's profile that you cannot view directly through facebook. (There is literature on the
web about that, about how to do it and how it's easier to bruteforce for timestamps than for truly randomly generated numbers
which facebook did not implement)

Some facebook pictures that you upload and later delete/ set to private still exist on facebook's 3rd party servers and can still be
viewed by the image URL links; further, they can be traced down to who uploaded them.
As a test, I uploaded an image, took note of its image URL and then deleted it from facebook. The image is still out
there in the image hosting servers as you can see here:

https://fbcdn-sphotos-a.akamaihd.net/hphotos-ak-ash4/321248_10150325810871234_515006233_8188580_1724070261_n.jpg


So, as a general rule, don't upload stuff you wouldn't be very uncomfortable with if made public.


- Gaurav




Note: This doesn't work for images uploaded prior to late 2009 or so, I think, since Facebook slightly changed the way the images
were organized on their storage servers.

Mais conteúdo relacionado

Mais procurados

Mc leod jamal_finalslideshow
Mc leod jamal_finalslideshowMc leod jamal_finalslideshow
Mc leod jamal_finalslideshowJTMcLeod
 
Why You Need An Agenda For Every Meeting
Why You Need An Agenda For Every MeetingWhy You Need An Agenda For Every Meeting
Why You Need An Agenda For Every MeetingSatoshi Takano
 
Interview Mastery - Satoshi Takano, Humber College
Interview Mastery - Satoshi Takano, Humber CollegeInterview Mastery - Satoshi Takano, Humber College
Interview Mastery - Satoshi Takano, Humber CollegeSatoshi Takano
 
5 Fails for Facebook Insights
5 Fails for Facebook Insights5 Fails for Facebook Insights
5 Fails for Facebook InsightsBen Bloom
 
Resume Writing Mastery - Humber College
Resume Writing Mastery - Humber CollegeResume Writing Mastery - Humber College
Resume Writing Mastery - Humber CollegeSatoshi Takano
 
Applying to Doctoral Programs: Crafting the Letter of Intent and Academic CV
Applying to Doctoral Programs: Crafting the Letter of Intent and Academic CVApplying to Doctoral Programs: Crafting the Letter of Intent and Academic CV
Applying to Doctoral Programs: Crafting the Letter of Intent and Academic CVLaurie Prange
 
Beyond Data: Building a Web of Needs
Beyond Data: Building a Web of NeedsBeyond Data: Building a Web of Needs
Beyond Data: Building a Web of Needsfkleedorfer
 
SlideShare for your Personal and Company Brand
SlideShare for your Personal and Company Brand SlideShare for your Personal and Company Brand
SlideShare for your Personal and Company Brand Sandra Long
 
How to Increase Your Influence at Work - An HBR Article Feb 2018
How to Increase Your Influence at Work - An HBR Article Feb 2018How to Increase Your Influence at Work - An HBR Article Feb 2018
How to Increase Your Influence at Work - An HBR Article Feb 2018Satoshi Takano
 
Employee Enablement on Social - Brand Advocates for Influence - Best Practices
Employee Enablement on Social - Brand Advocates for Influence - Best PracticesEmployee Enablement on Social - Brand Advocates for Influence - Best Practices
Employee Enablement on Social - Brand Advocates for Influence - Best PracticesMarcus Nelson
 
Michael Fraser Leicestershire and Rutland Chess Association
Michael Fraser Leicestershire and Rutland Chess AssociationMichael Fraser Leicestershire and Rutland Chess Association
Michael Fraser Leicestershire and Rutland Chess Associationaleahlawrencetsv
 
Employer Branding: Do you Know the Origins?
Employer Branding: Do you Know the Origins?Employer Branding: Do you Know the Origins?
Employer Branding: Do you Know the Origins?Sandra Long
 
Fokus - smarter analytics na Aula Polska Poznań
Fokus - smarter analytics na Aula Polska Poznań Fokus - smarter analytics na Aula Polska Poznań
Fokus - smarter analytics na Aula Polska Poznań Aula Polska Poznań
 
Applying to Doctoral Programs: Discussing the Decision With Others
Applying to Doctoral Programs: Discussing the Decision With OthersApplying to Doctoral Programs: Discussing the Decision With Others
Applying to Doctoral Programs: Discussing the Decision With OthersLaurie Prange
 
Stressless Paperless
Stressless PaperlessStressless Paperless
Stressless Paperlessconcretekax
 
Applying to Doctoral Programs: Reference Letters
Applying to Doctoral Programs: Reference LettersApplying to Doctoral Programs: Reference Letters
Applying to Doctoral Programs: Reference LettersLaurie Prange
 

Mais procurados (20)

Mc leod jamal_finalslideshow
Mc leod jamal_finalslideshowMc leod jamal_finalslideshow
Mc leod jamal_finalslideshow
 
Cybersecurity - NSA Style
Cybersecurity - NSA StyleCybersecurity - NSA Style
Cybersecurity - NSA Style
 
Why You Need An Agenda For Every Meeting
Why You Need An Agenda For Every MeetingWhy You Need An Agenda For Every Meeting
Why You Need An Agenda For Every Meeting
 
Interview Mastery - Satoshi Takano, Humber College
Interview Mastery - Satoshi Takano, Humber CollegeInterview Mastery - Satoshi Takano, Humber College
Interview Mastery - Satoshi Takano, Humber College
 
5 Fails for Facebook Insights
5 Fails for Facebook Insights5 Fails for Facebook Insights
5 Fails for Facebook Insights
 
Resume Writing Mastery - Humber College
Resume Writing Mastery - Humber CollegeResume Writing Mastery - Humber College
Resume Writing Mastery - Humber College
 
How to Twitter
How to TwitterHow to Twitter
How to Twitter
 
Applying to Doctoral Programs: Crafting the Letter of Intent and Academic CV
Applying to Doctoral Programs: Crafting the Letter of Intent and Academic CVApplying to Doctoral Programs: Crafting the Letter of Intent and Academic CV
Applying to Doctoral Programs: Crafting the Letter of Intent and Academic CV
 
Beyond Data: Building a Web of Needs
Beyond Data: Building a Web of NeedsBeyond Data: Building a Web of Needs
Beyond Data: Building a Web of Needs
 
Fresh Lemona.de
Fresh Lemona.deFresh Lemona.de
Fresh Lemona.de
 
SlideShare for your Personal and Company Brand
SlideShare for your Personal and Company Brand SlideShare for your Personal and Company Brand
SlideShare for your Personal and Company Brand
 
How to Increase Your Influence at Work - An HBR Article Feb 2018
How to Increase Your Influence at Work - An HBR Article Feb 2018How to Increase Your Influence at Work - An HBR Article Feb 2018
How to Increase Your Influence at Work - An HBR Article Feb 2018
 
Employee Enablement on Social - Brand Advocates for Influence - Best Practices
Employee Enablement on Social - Brand Advocates for Influence - Best PracticesEmployee Enablement on Social - Brand Advocates for Influence - Best Practices
Employee Enablement on Social - Brand Advocates for Influence - Best Practices
 
Michael Fraser Leicestershire and Rutland Chess Association
Michael Fraser Leicestershire and Rutland Chess AssociationMichael Fraser Leicestershire and Rutland Chess Association
Michael Fraser Leicestershire and Rutland Chess Association
 
Employer Branding: Do you Know the Origins?
Employer Branding: Do you Know the Origins?Employer Branding: Do you Know the Origins?
Employer Branding: Do you Know the Origins?
 
Fokus - smarter analytics na Aula Polska Poznań
Fokus - smarter analytics na Aula Polska Poznań Fokus - smarter analytics na Aula Polska Poznań
Fokus - smarter analytics na Aula Polska Poznań
 
Applying to Doctoral Programs: Discussing the Decision With Others
Applying to Doctoral Programs: Discussing the Decision With OthersApplying to Doctoral Programs: Discussing the Decision With Others
Applying to Doctoral Programs: Discussing the Decision With Others
 
Stressless Paperless
Stressless PaperlessStressless Paperless
Stressless Paperless
 
Applying to Doctoral Programs: Reference Letters
Applying to Doctoral Programs: Reference LettersApplying to Doctoral Programs: Reference Letters
Applying to Doctoral Programs: Reference Letters
 
Twitter for Beginners
Twitter for BeginnersTwitter for Beginners
Twitter for Beginners
 

Último

Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Zilliz
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...apidays
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamUiPathCommunity
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024The Digital Insurer
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...apidays
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdfSandro Moreira
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native ApplicationsWSO2
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfOrbitshub
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingEdi Saputra
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDropbox
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfOverkill Security
 

Último (20)

Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 

Facebook Geek Tricks - Pictures

  • 1. Intro to Facebook Stalking - Pictures - Gaurav Ragtah When someone sends you a facebook image URL (ie. just the image opens in the browser, and nothing else), it looks something like this: https://fbcdn-sphotos-a.akamaihd.net/hphotos-ak-snc6/216083_10150177890751234_515006233_6971227_4935405_n.jpg (you can get an image URL by right clicking on an image in facebook and selecting 'copy image URL') Now, notice the part of the URL after the last '/' :216083_10150177890751234_515006233_6971227_4935405_n.jpg There are five numbers here. The first, fourth and fifth are timestamp generated by facebook when one uploads an image. The second and third numbers, however, are the picture id and the user profile id (person who uploaded the image) respectively. So to see the actual image in the album context, plug in the 2nd number into https://www.facebook.com/photo.php?fbid= which in our case will be https://www.facebook.com/photo.php?fbid=10150177890751234 AND to see the user profile of the person who uploaded the picture, plug in the 3rd number from the image URL into https://www.facebook.com/profile.php?id= which in our case will be https://www.facebook.com/profile.php?id=515006233 VOILA!! ;) Happy facebook-ing. Read on: Now, a bruteforce script can be easily written to generate timestamps to plug-in for the Image URLs so that you can possibly view and download private images from someone's profile that you cannot view directly through facebook. (There is literature on the web about that, about how to do it and how it's easier to bruteforce for timestamps than for truly randomly generated numbers which facebook did not implement) Some facebook pictures that you upload and later delete/ set to private still exist on facebook's 3rd party servers and can still be viewed by the image URL links; further, they can be traced down to who uploaded them. As a test, I uploaded an image, took note of its image URL and then deleted it from facebook. The image is still out there in the image hosting servers as you can see here: https://fbcdn-sphotos-a.akamaihd.net/hphotos-ak-ash4/321248_10150325810871234_515006233_8188580_1724070261_n.jpg So, as a general rule, don't upload stuff you wouldn't be very uncomfortable with if made public. - Gaurav Note: This doesn't work for images uploaded prior to late 2009 or so, I think, since Facebook slightly changed the way the images were organized on their storage servers.