7 ms·
Yes, I just found out yesterday that setting your referrer to facebook.com/l.php allows you to reliably bypass the paywall. E.g. http://facebook.com/l.php?u=ht
by ctrl_freak 10y ago
Yes, I just found out yesterday that setting your referrer to facebook.com/l.php allows you to reliably bypass the paywall.
E.g. http://facebook.com/l.php?u=http://www.wsj.com/articles/political-world-embraces-encrypted-messaging-app-amid-fears-of-hacking-1485492485 http://facebook.com/l.php?u=http://www.wsj.com/articles/poli...
- abofh 10y agoWow, I don't even have a facebook account and that works. That feels like some XSS waiting to happen :/
- Buge 10y agoIt's an open redirect, not XSS. It's a matter of debate whether an open redirect is a vulnerability or not.
- ufmace 10y agoThanks, that does work. Though I still feel a little funny about jumping through a bunch of weird hoops to read news articles.
- throwaway40483 10y agoThis trick is the only thing that seems to bypass WSJ paywall now
- ufmace 10y agoIn case anyone's still here, I made a bookmarklet for it: javascript:location.href='http://facebook.com/l.php?u='+encodeURIComponent(location.href) http://facebook.com/l.php?u='+encodeURIComponent(location.hr... Make a bookmark with that, call it I'm from Facebook or something, and go to it when you hit a paywall.