6 ms·
A look inside Facebook's source code
- Buge 12y agoReminds me somewhat of this https://twitter.com/dumpmon https://twitter.com/dumpmon which monitors all pastes for email and password dumps. You can use https://haveibeenpwned.com/ https://haveibeenpwned.com/ to search if your email has ever been leaked/dumped.
- anw 12y agoInteresting. It's also interesting that Facebook developers are using Pastebin for things such as this. I would assume that they'd have an internal wiki, or gist-like app. It's also noteworthy to see how they set up their accounts: first initial, full lastname—same standard as many other companies. But seeing it laid out can help in the guessing of other names (or common name occurances, as you don't even need a full first name). While some leaks may not even be effective outside Facebook's internal network (things such as database credentials, network shares… hopefully), having actual code that may be in production does pose a risk. The possiblity to see where, for instance, data isn't fully sanitized, or where information being fetched might not require proper authentication[1] is more worrying. Facebook is known for promoting "move fast and break things". Hopefully they have good QA and SDET teams to catch these things. [2] One code snippet features the following: > // TODO: add privacy checks!
- rjayatilleka 12y agoI'm not surprised they don't have a gist/pastebin like app. When I interned at Amazon this summer, they were just developing one, and it was still pretty alpha (persistence was buggy and lost me an entire design review of notes). Facebook is younger, so it seems fair that they don't have one.
- TTPrograms 12y agoFacebook has been around for a decade at this point. Youth isn't much of an excuse.
- prab97 12y agoThat's wrong. I have been here since June 2012 and we have internal paste.
- serge2k 12y agoamazon's internal tool works fine.
- lstamour 12y agoSpeaking of the TODO, I particularly liked how the diff suggests removing it ;-) That said, it did appear to be some kind of "enterprise" version maybe?
- spicyj 12y agoThe diff suggests removing the TODO because it adds the privacy checks. See the added canSeeFriends call.
- AdamGibbins 12y agoFacebook do have an internal pastebin, its part of their Phabricator suite, called Paste - http://phabricator.org/applications/ http://phabricator.org/applications/
- underwater 12y agoWe have an internal pastebin, it's built into Phabricator. There is no preset format for unixnames. Most people use their names but I've seen many pseudonyms. One intern famously broke some internal tools by requesting her initials, which were "www".
- dsl 12y agoI broke more than my fair share of systems by using "Roger Oot" as my goto pseudonym.
- desdiv 12y agoSorry, I don't get it. Could you please explain it?
- jsprogrammer 12y agoUnwittingly using Magic Character Sequences counts as breaking internal tools? More like exposed implementation and/or design flaws in internal tools.
- bmeckel 12y agoPastebin has TONS of stuff lying around, it's pretty fascinating. I've always wanted to spend some time digging around there, but haven't gotten around to it.
- misiti3780 12y agois there a public api? EDIT - there is - i had no clue: http://pastebin.com/api#1 http://pastebin.com/api#1
- misiti3780 12y agofascinating stuff. I'm still amazed at how many username/passwords are freely available via github search: https://github.com/search?p=96&q=gmail+password&ref=searchresults&type=Code&utf8=%E2%9C%93 https://github.com/search?p=96&q=gmail+password&ref=searchre... even if they have 2-step auth setup, people choose "complete the email address" as a form of authentication which you can most likely get from their github profile. the moral of the story here is - if you do not want someone to find it - do not publish it online
- rankam 12y agoI understand you're just showing how easy it is to find email/password combinations, but maybe it isn't the best idea to post an example link on how to do it?
- lstamour 12y agoShoot. I guess I shouldn't post the advanced search I just tried. Let's just say I had 12,875 search results for a common CMS' configuration files ... it was scary how easy it was, actually, to filter the results down to what I was looking for. Github ought to put up a warning saying, "you have a wp-config.php file, you know this is public right? Here's how to use .gitignore" and a link, or something.
- misiti3780 12y agoall i did was search "gmail password" in github search and paste the url here - this is not rocket science
- icpmacdo 12y agoIm not a hacker/cracker or whatever but I am curious would it be illegal to use one of those usernames and passwords to see if it actually worked for an account? edit: I know that it is not ethical and I am only slightly tempted to do it but is it actually illegal to use open source code in that way?
- IkmoIkmo 12y ago
- Alex3917 12y agoSomewhat ominous for top HN users: http://pastebin.com/6GeZnS9b http://pastebin.com/6GeZnS9b
- shitlord 12y agoI like that this was written in javascript. Was it meant to be injected onto webpages MITM-style?
- Alex3917 12y agoThe ID selectors would correspond to a form on a separate webpage, which the author is using jQuery to manipulate, so no injection.
- ssclafani 12y agoThis was someone's attempt at a bitcoin public challenge: https://news.ycombinator.com/item?id=6765801 https://news.ycombinator.com/item?id=6765801 (Get a wallet's passphrase which was the username of someone in the Hacker News top 100, minus 2 characters).
- petercooper 12y agoWas amused to click through and see it was my username involved. Mostly as I gave up ever trying to do anything with Bitcoin because I simply can't get my head around any of the practicalities, lol, so it definitely wasn't anything of mine! ;-)
- Kiro 12y agoI don't understand.
- shaunpud 12y agoPart 2; http://sintheticlabs.com/blog/a-look-inside-facebooks-source-code-part-2.html http://sintheticlabs.com/blog/a-look-inside-facebooks-source...
- pilif 12y agoTangentially related, I'd like an opinion on this: >Okay, so it's not the most secure password. But Facebook's database servers are heavily firewalled. Though if you do manage to break in to Facebook's servers, there's the password. What is the point on even having a database password? The application itself needs access to the database, so the application needs to know the password. That means that an attacker who gains access to the application can easily just look at the file where the password is stored and then use that to access the database. Even if you'd go great lengths at keeping asking for the password at server start and only keeping it in memory - once an attacker is on the application server, the password is in memory and can be snooped. So the question is: Why even use a password for the web application? In my case, I'll just let the application servers connect to the database without password.
- raverbashing 12y agoDifferent access levels? (your app may not have the right to erase data/drop tables for example) Auditing (per tool)? Not all attackers come "through the front door"
- pilif 12y agoYes. But I'm talking about the password for the account that the web application itself is using. That one IMHO is superflous. Other access levels, of course, might require a password.
- raverbashing 12y agoAh I see your point, it might be a good idea, to make the webapp account have the least amount of privileges possible.
- dsl 12y agoA password means you can't access the database server from a mail server or file server. Complex environments have more than just a database server and a few web servers.
- superasn 12y agoI found an interesting post from "karthimx" [1] made on Jun 30, 2010. It too contains the password "e5p0nd4". This user didn't do any hacking or googling but got this error browsing facebook. He says "Suddenly I got this error message in Facebook" (so apparently inside the production environment, wtf?). [1] https://forums.digitalpoint.com/threads/facebook-error-message.1855399/ https://forums.digitalpoint.com/threads/facebook-error-messa... [2] http://www.zyngaplayerforums.com/archive/index.php/t-545034-p-3.html http://www.zyngaplayerforums.com/archive/index.php/t-545034-... - Another one from 2010!