Facebook Bug Allowed to Get Any User's Friend List and Partial Payment Card Details.

in #news7 years ago

Friend list disclosure using persisted GraphQL queries and first-party application client tokens
Facebook has a GraphQL endpoint which can only be used by some of their own first-party applications. Generally, you need a user (or page) access_token to query the GraphQL endpoint. I have decided to try using Facebook for Android application's client token, but the endpoint returned an error message:

Sans titreml.png

================
read from source :
================
https://www.josipfranjkovic.com/blog/facebook-friendlist-paymentcard-leak

Sort:  

hahaha luckily i left Facebook years ago - only using diaspora* and Mastodon these days - dude i love Mastodon.

i will check that ;) thank you