Top Friends on Facebook

Date: February 4, 2008

Initial hack: 15-20 minutes

Vulnerabilities:

  • Able to access Top Friends information (e.g. the user’s top friends, who the user is a top friend of) for any user

Progress: Slide, Inc. has been notified.

Details: Can you tell I’m playing with Facebook apps tonight?  This hack uses the same kind of technique as the iLike on Ning hack.  It allows one to view a user’s selected “top friends,” even if that user’s normal friend list is inaccessible directly.

One Response to “Top Friends on Facebook”

  1. Social Hacking » Blog Archive » Quick Update on Top Friends Says:

    [...] no doubt heard about the Top Friends application getting banned.  In the past I’d pointed out that you could access application data about other users, but that was before Slide created [...]

Leave a Reply

Checking the security and privacy of social networking applications, white hat style…