Facebook exploit – Confirm website visitor identities
I searched across the site looking for any endpoints that didn’t have these protections and which did pass my user id in the URL, looking for any way I may be able to parse a response from Facebook to confirm whether the UID in the URL was correct. After carefully checking dozens of these endpoints I eventually found one that had a slight inconsistency in how it behaved which was a small gap but represented a weakness; it did have an header, but it only included a magic prefix when the user ID (in the URL parameter) didn’t match, not when it did match. Here is an example of the URL for the endpoint:
I was then able to craft a simple Javascript script that would take a list of user IDs and generate many script tags with callbacks to determine success or failure.
Source: www.tomanthony.co.uk