PaulDotCom mailing list archives

Re: Facebook account harvesting


From: Larry Pesce <larry () pauldotcom com>
Date: Tue, 27 Jul 2010 11:50:37 -0400

Ron, awesome work. I got my copy via torrent, and now I'm seeding at
about 700K/sec@  O_o

I can't wait for folks to start digging into this dataset (myself
included) to see what we can come up with.

- L

On 7/27/10 8:22 AM, Ron wrote:
Hey everybody,

I spent some time recently spidering Facebook to get every person's name who has an account and is searchable. I 
released the data from phase 1 of that project today, and thought I'd share:
http://www.skullsecurity.org/blog/?p=887

Besides shameless self promotion (which I enjoy more than I can say ;) ), this can be exceptionally helpful if you're 
going into a bruteforce against a company blind, and you have some way of finding out their username convention. I 
pre-calculated first initial/last name, first name/last initial, and first name dot last name. I included the raw 
data so you can process it yourself. 

If you want the raw data (and even if you don't ;) ), grab the .torrent from the blogpost and let it download that 
way. Nobody I know had enough bandwidth to serve hundreds of megabytes worth of files. 

Let me know what you think! Phase 2 of my collection is going to start after Defcon is over and I'm safely back home. 
Hope to see you all there! (Defcon, I mean, not my home)

_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com


Current thread: