Top Friends on Facebook

Date: February 4, 2008

Initial hack: 15-20 minutes

Vulnerabilities:

  • Able to access Top Friends information (e.g. the user’s top friends, who the user is a top friend of) for any user

Progress: Slide, Inc. has been notified.

Details: Can you tell I’m playing with Facebook apps tonight?  This hack uses the same kind of technique as the iLike on Ning hack.  It allows one to view a user’s selected “top friends,” even if that user’s normal friend list is inaccessible directly.

Leave a Reply

Checking the security and privacy of social networking applications, white hat style…