The Hive
GitHubLinkedInEmail
  • 🏠Home
  • 🌐RECON
    • 📡Passive (OSINT)
      • ⏩Metadata
      • ⏩Social Platforms
        • Email
        • Tumbler
        • Redit
        • Github
        • Tinder
        • TikTok
        • Snapchat
        • Instagram
        • Facebook
        • Twitter
        • Google
        • LinkedIn
    • 📡Active
      • ⏩Host Discovery / Network Mapping
      • ⏩nmap cheat sheet
      • ⏩masscan cheat sheet
    • 📡Web Recon
      • ⏩Web Server Discovery
      • ⏩Hidden Hosts
      • ⏩Directories & Subdomains
      • ⏩SSL Certs
      • ⏩CMS
      • ⏩WAF Detection
    • 📡Firewall Evasion
  • 📗Web Attacks
    • 🟢Server Side
      • 🟩Authentication Mechanisms
      • 🟩Access Control (Authorization)
      • 🟩Directory Traversal
      • 🟩OS Command Injection
      • 🟩Server-Side Request Forgery (SSRF)
      • 🟩XML External Entity (XXE) Injection
      • 🟩File Upload
      • 🔧SQL Injection
      • 🟩Information Disclosure
      • 🟩Business Logic
    • 🟢Client Side
      • 🟩Cross-site request forgery (CSRF)
      • 🔧Cross-site scripting (XSS)
  • 📒Network attacks
    • 🟡Network Services
      • 🟨Brute Force
      • 🟨DNS
      • 🟨IPv6
      • 🟨FTP
      • 🟨SSH
      • 🟨SMB
      • 🟨SNMP
      • 🟨SMTP
      • 🟨POP3
      • 🟨IMAP
      • 🟨MSSQL
      • 🟨MySQL
      • 🟨MSRPC / RPCbind
      • 🟨LDAP
      • 🟨NTP
      • 🟨NFS
      • 🟨Telnet
      • 🟨WebDAV
      • 🟨RDP
      • 🟨RSIP
      • 🟨Rlogin
      • 🟨VPNs
      • 🟨Echo
      • 🔧RTP
      • 🔧VOIP
        • SIP
    • 🟡Network Devices
      • 🟨IPv6 Attacks
        • Neighbor Impersonation
        • Router Advertisement Flooding
      • 🟨Switch Attacks
        • Cisco Exploitation
        • STP Spoofing
        • VLAN Hopping
        • MAC Flood
      • 🟨Router Attacks
        • Router Exploitation
        • HSRP Hijacking
        • 🔧RIP Spoofing
        • 🔧OSPF Attacks
        • 🔧VRRP MitM
      • 🟨NAC Bypass
        • Captive Portal
        • 802.1X / EAP Bypass
      • 🟨Printer Exploitation
    • 🟡MITM & Poisoning
      • 🟨Bettercap
      • 🟨HTTPS Downgrade / HSTS Bypass
      • 🟨Session Hijackings
      • 🟨Malicious Update
      • 🟨RDP Downgrade
      • 🟨DNS Spoofing
      • 🟨NTP Spoofing
      • 🟨ARP Spoofing
      • 🟨DHCP Poisoning
      • 🟨DHCPv6 Spoofing
      • 🟨SSDP Spoofing
      • 🟨WSUS Spoofing
      • 🟨ADIDNS Poisoning
      • 🟨WPAD Abuse
    • 🟡Wireless Attacks
      • 🟨Protocol Concepts
      • 🟨Basics
      • 🟨Attacks
    • 🟡Sniffing
      • 🟨Wireshark
      • 🟨tcpdump
    • 🟡Denial of Service
  • 📕Red Team
    • 🔴Windows
      • ⭕Security Concepts
        • Windows Security Components
        • Active Directory Components
        • Kerberos
        • Loggon Sessions and Access Tokens
        • Permissions and Access Control
        • Windows Registry
        • Object Management
      • ⭕Physical Attack
      • ⭕Enumeration
      • ⭕Privilege Escalation
        • DLL Hijacking
          • Phantom DLL Hijacking / Replacement
          • Search Order Hijacking ( Preloading )
          • DLL Side-Loading
        • Service Misconfigurations
          • Weak Registry Permissions
          • Insecure Service Executables
          • Insecure Permission
          • Unquoted Service Path
        • Creating a New Service (admin to system)
        • Registry
          • AlwaysInstallElevated
          • AutoRuns
        • Scheduled Tasks
        • Mass Roll-outs
        • Startup Apps
        • Installed Applications
        • Loopback Services
        • Insecure GUI APPs
        • Potatos
        • Printspoofer / SEImpersonate
        • PSEXEC (admin to system)
      • ⭕Credential Dumping
      • ⭕Persistence
        • Invisible Account Forger
        • Add User
        • Scheduled Tasks
        • Run Registry Keys
        • Logon Scripts
        • Screensavers Hijack
        • Powershell Profiles & Modules
        • Service Creation/Modification
        • Shortcut Modification
        • Startup Folder
        • RDP backdoors
        • COM Hijacking
    • 🔴Active Directory
      • ⭕Domain Enumeration
      • ⭕Tools & Frameworks
        • Evil-WinRM
        • CME cheat sheet
        • SharpSploit
        • impacket cheat sheet
        • DeathStar
      • ⭕Exploitation
        • LLMNR Poisoning
        • SMB/NTLM Relay
        • DNS Takeover + LDAP Relay
        • Cracking Hashes
        • Password spraying
        • ADCS + PetitPotam NTLM Relay
        • EternalBlue
        • ZeroLogon
        • MS Exchange ProxyShell
        • MS Exchange ProxyLogon
        • Java JBOSS
      • ⭕Privilege Escalation
        • Token Impersonation
        • DNS Admins
        • AD CS Abuse
        • ACL Abuse
          • GenericAll
          • Write Property
          • Self-membership
          • ForceChangePassword
          • Managed Security Groups
          • Exchange Windows Permissions
        • Group Policy Objects (GPOs)
        • Custom SSPs
        • PrintNightmare
      • ⭕Lateral Movement
        • RDP Password Decryption
        • RDP Session Hijacking
        • headless RDP with SharpRDP
        • Domain Shares
        • SCF File Attacks
        • Pass the Hash / Password
        • Overpass the Hash / Pass the Key
        • Pass The Ticket
        • Kerberosting / AS-REP Rosting
        • Kerberos Delegation
      • ⭕Credential Dumping
        • CredSSP / TSPKG
        • Wdigest Clear Text
        • DPAPI secrets
        • SAM & Registry
        • NTDS.dit & vshadow
        • comsvcs.dll
        • Meterpreter
        • Procdump & LSASS
        • AD User Comments
        • SYSVOL & Group Policy Preferences
        • LAPS Passwords
        • GSMA Passwords
        • HiveNightmare
        • Mimikatz Cheat sheet
        • Other Tools / Techniques
      • ⭕Persistence
        • Certificates
        • DCSync
        • DCShadow
        • Silver Ticket
        • Golden Ticket
        • Skeleton Key
        • WMI
        • PowerShell Remoting
        • Remote Registry
        • Rights Abuse
        • AdminSDHolder
        • DSRM
        • Kerberos Checksum Validation ( MS14-068 )
    • 🔴Linux
      • ⭕Physical Attacks
      • ⭕Enumeration
      • ⭕Privilege Escalation
        • SUID / SGID abuse
        • /etc/shadow & /etc/passwd
        • cron/crontab abuse
        • Sudo Abuse
        • Capabilities Abuse
        • Environment Variables
          • LD_LIBRARY_PATH
          • LD_PRELOAD
        • Shared Object Injection
        • NFS
        • man CE Pager Argument
        • MySQL UDF
        • UDEVD
        • STDIN/STDOUT
        • Unix Socket Exploitation
        • Dirty Pipe
        • Docker
          • SUID Docker
      • ⭕Lateral Movement
        • Infecting Running Processes
        • VIM Config File Keylogger
        • SSH Hijacking
        • Samba Secrets to Domain Admin
        • Hiding Processes
        • Simple User-mode Rootkits
        • Vino VNC Server
      • ⭕Credential Dumping
        • Swap Dump
        • mimipinguin
        • unshadow
        • 3snake
      • ⭕Persistence
        • Startup User File Backdoor
        • PHP Backdoor
        • Apache mod_rootme
        • Startup Service Backdoor
        • xdg Backdoor
        • rootbash SUID
        • apt Backdoor
        • Driver Backdoor
        • Core Pattern
        • dash Backdoor
        • Creating an SUID Binary
        • Systemd netcat bind shell
        • Xinetd UDP portnock
        • openSSL reverse shell
        • motd Backdoor
        • Auth Log Backdoor
        • RSYSLOG Backdoor
        • sshd Backdoor
        • VIM Config Backdoor
        • .bashrc Backdoor
        • Adding a Root user
        • Crontab Reverse Shell
        • SSH persistence password-less
      • ⭕Covering Tracks
    • 🔴Command & Control (C2)
      • ⭕Cobalt Strike
      • ⭕Metasploit
      • ⭕Empire & Starkiller
      • ⭕Covenant
    • 🔴Shells and Payloads
      • ⭕Shell Escape / Interactive Shell
      • ⭕LOL Binaries
      • ⭕msfvenom
      • ⭕SharpShooter & Ivy
      • ⭕Other Payloads
    • 🔴Payload Delivery
      • ⭕Powershell Reflective DLL Load
      • ⭕HTML Smuggling
      • ⭕Office Macros
      • ⭕DDE Auto - Word/Excel
      • ⭕.SLK Excel
      • ⭕XLM Macro 4.0
      • ⭕LNK
      • ⭕embedded OLE + LNK objects
      • ⭕JScript
      • ⭕HTA
      • ⭕VBS
      • ⭕VBA
      • ⭕RTF
      • ⭕REG
      • ⭕MSI / MSIEXEC
      • ⭕IQY
      • ⭕CHM / HHC
      • ⭕SCR
    • 🔴Pivoting
      • ⭕SSH Forwarding
      • ⭕Socat Stealth Port Forward
      • ⭕Socat Reverse Shell Relay
      • ⭕HTTP Tunneling
      • ⭕ICMP Tunneling
      • ⭕DNS Tunneling
      • ⭕Metasploit Pivoting
      • ⭕Cobalt Strike Pivoteing
      • ⭕VPN Tunneling
      • ⭕Other Tools
    • 🔴Exfiltration / File Transfer
      • ⭕Encode / Decode Files
      • ⭕TCP / UDP
      • ⭕DNS
      • ⭕SSH
      • ⭕ICMP
      • ⭕SMB
      • ⭕FTP
      • ⭕HTTP
      • ⭕Other Methods
    • 🔴Password Attacks
      • ⭕Online Attacks
      • ⭕Offline Attack
      • ⭕Word List
      • ⭕Cheat Sheet
    • 🔴Defense Evasion
      • ⭕Basic Tricks
      • 🔧Powershell Tricks
      • ⭕Disabling Defenses
      • ⭕UAC Bypass
      • ⭕Process Migration
      • ⭕Dechaining Macros
      • ⭕VBA Sandbox Evasion
      • ⭕AMSI Bypass
      • ⭕SRP & AppLocker Bypass
      • ⭕GPO Bypass
  • 📘Blue Team
    • 🔵Threat Modeling / Hunting / Intelligence
    • 🔵Linux Hardening
      • 🔹OS Security
        • Update Strategy
        • Service Management
        • Physical Security
        • Grub Hardening
        • Kernel Parameters
        • Process Isolation
      • 🔹Accounts & Passwords
        • Users & Groups
        • Password Security & Sudoers
      • 🔹Access Control & Ownership
      • 🔹File System Security
      • 🔹Integrity Check
      • 🔹Sandboxing
      • 🔹Network
      • 🔹iptables
        • Rule Sets
      • 🔹Service Hardening
        • BIND9
        • vsftpd
        • Nginx
        • Apache
        • SSH
      • 🔹System Audit
      • 🔹Logging
        • auditd
      • 🔹Encryption
    • 🔵Security Architecture
      • 🔹Layered Security
  • 🟪Purple Teaming
    • 🟣Adversary Emulation
  • 🟧programming
    • 🟠C Programming
      • 🔸Basic Structure
      • 🔸GCC Compiler
      • 🔸Preprocessors
      • 🔸Data Types
      • 🔸Type Qualifiers
      • 🔸Pointers
      • 🔸Dynamic Memory Allocation
      • 🔸Loops
      • 🔸Conditional Statements
      • 🔸Functions
      • 🔸Input / Output
      • 🔸Macros
      • 🔸Files
      • 🔸Strings Manipulation
      • 🔸Bit Manipulation
      • 🔸Data Structures
        • Arrays
        • Structures
        • Unions
      • 🔸Abstract Data Types
        • Stack
        • Queue
        • Linked List
          • Singly Linked List
          • Doubly Linked List
      • 🔸Libraries & Linking
      • 🔸Error Recovery
    • 🔧Assembly ( NASM )
      • Intel IA-32 Environment
      • Basic Structure
      • Variables and Data Types
      • Most-used Instructions
      • input / output
  • 🟫Miscellaneous
    • 🟤GNU Screen / tmux
    • 🟤SSH Tricks
    • 🟤Cats
      • netcat
      • ncat
      • pwncat
      • socat
      • 🔧powercat
    • 🟤Curl
    • 🟤Cross-compiling Binaries
Powered by GitBook
On this page
  1. RECON
  2. Passive (OSINT)
  3. Social Platforms

Facebook

Tips & Tricks

# Stalking and Information Gathering
https://stalkscan.com/

# Facebook video downloader
https://fbdown.net/

# Find Facebook ID
https://findmyfbid.com
https://lookup-id.com/

# Facebook tool for multi searches
https://whopostedwhat.com/

# You can search for Facebook videos indexed on Google
"topic" site:facebok.com!/*/videos

# Source + script to do that
https://twitter.com/lorenzoromani/status/1301843624230035456?s=19
https://github.com/lorenzoromani1983/facebookTranscripts/blob/master/facebookTranscripts.py

# DumpItBlue Extension
# Facebook tool box
https://le-tools.com/DumpItBlueExtensionDoc.html

Facebook Tricks

# You can search by e-mail

# You can find accounts by e-mail with the recover function
https://www.facebook.com/login/identify?ctx=recover
https://www.facebook.com/login/identify

# Search photo by ID
https://www.facebook.com/photo.php?fbid=PHOTO-ID-HERE

# You can search for car using plate number
# For example ST-597-NS will give you car photos identified with relating plate number

# You can search by text on Google for indexed videos
Example: "hacking" site:http://facebook.com/*/videos.

# You can also search for unique identifier
# Even if they're not tagued
https://twitter.com/quiztime/status/1339544098529832969

Facebook Sleep Stats

# A small tool to show the potential privacy implications modern social media have. 
# By tracking online/offline status of people on Facebook, it is possible to get an accurate image of their sleep pattern.
https://github.com/sqren/fb-sleep-stats

# Two process are running simultaniously : scrapper and webserver
# Scraping
npm run scrape

# Server (localhost:3000)
npm start

# Ad blocker must be disabled
# When the scrapper is off, it stops tracking

Ultimate Facebook Scraper

# Python automated script used to scrape and parse data from a Facebook account
# You need to provide your credentials (dedicated account) and targets as input in "input.txt".

# Limits : 
# - If the profile target is configured and not in your friends, you may see nothing
# - If you request too much profiles, Facebook can block requests, resulting in crash
# - If target profiles are big, can be very long an resources hungry

# Results are stored in txt format, easily grepable by dates for examples.

Facebook Graph Search

# Graph Search is a Facebook internal search engine used to get precise results when searching
# Facebook need to be in English version to activate the Graph Search

# On June 2019, Facebook shut down its Graph Search options.
# The ‘new’ Graph Search seems a little comprehensive at first
# but it’s pretty easy once you get the hang of it. It involves some JSON and Base64.

The New Graph Search Methods

# Resources
https://osintcurio.us/2019/08/22/the-new-facebook-graph-search-part-1/
https://osintcurio.us/2019/08/22/the-new-facebook-graph-search-part-2/

# Tools
https://graph.tips/beta/
https://intelx.io/tools?tab=facebook
# Identifiers are always required to performs queries
# CTRL+U on page, profile, group...
# CTFL+F 
# "entity_id" = Profile 
# "page_id" = Page
# "group_id" = Group

# EVERY Facebook requests start like this
facebook.com/search/top/?q=people&epa=FILTERS&filters=

# top/  Search top content
# posts/    Search public posts
# people/   Search for people
# photos/   Search for photos
# videos/   Search for videos
# pages/    Search for pages
# places/   Search for places

# And then the content of the query
facebook.com/search/posts/?q=baseball&epa=FILTERS&filters=

# It uses then JSON and BASE64 to apply filters
# For example, the JSON string for "most recent" is
{“rp_chrono_sort”:”{\”name\”:\”chronosort\”,\”args\”:\”\”}”}

# Then base64 encode it
facebook.com/search/posts/?q=baseball&epa=FILTERS&filters=<BASE64>

# You can also perform combined queries
# Example : From one city and one employer
{“city”:”{\”name\”:\”users_location\”,\”args\”:\”108212625870265\”}”}
{“employer”:”{\”name\”:\”users_employer\”,\”args\”:\”104958162837\”}”}
# Result
{“city”:”{\”name\”:\”users_location\”,\”args\”:\”108212625870265\”}”,”employer”:”{\”name\”:\”users_employer\”,\”args\”:\”104958162837\”}”}

# Think about testing queries
https://jsonformatter.curiousconcept.com/

# And then concat with a classic query
facebook.com/search/posts/?q=baseball&epa=FILTERS&filters=<BASE64>

# Some queries
# Most recent populair content
{“rp_chrono_sort”:”{\”name\”:\”chronosort\”,\”args\”:\”\”}”}

# Most populair public content
{“rp_author”:”{\”name\”:\”merged_public_posts\”,\”args\”:\”\”}”}

# Most populair content viewed by your profile
{“interacted_posts”:”{\”name\”:\”interacted_posts\”,\”args\”:\”\”}”}

# Posts from your friends
{“rp_author”:”{\”name\”:\”author_friends_feed\”,\”args\”:\”\”}”}

# Posts from the pages you like and the groups you are a member of
{“rp_author”:”{\”name\”:\”my_groups_and_pages_posts\”,\”args\”:\”\”}”}

# People who work at a specific employer
{“employer”:”{\”name\”:\”users_employer\”,\”args\”:\”PutIDHere\”}”}

# Photos viewed by your profile
{“interacted_posts”:”{\”name\”:\”interacted_posts\”,\”args\”:\”\”}”}

# Photos posted by your friends
{“rp_author”:”{\”name\”:\”author_friends_feed\”,\”args\”:\”\”}”}

Old Graph Search

# Classic requests are like in natural language
Photos of my friends

# But some requests give bad results or false positive
# Alternative is using the Graph Search through the URL
facebook.com/search/str/<search>
# Track you Facebook activity
My favorites pages
My favorites music
Books I like
Photos I have liked
Photos have I like that are recent
Places visited by me
Places nearby I visited
Games I like
...
# View photos of friends or even strangers
Photos of my friends
Photos of my friends of friends taken in <Place>
Photos of people named [Name]
Photos of (or uploaded by) [Name]
Photos of [Name] in (or before or after) [Year]
Photos commented on by [Name]
Photos liked by [Name]
Photos of [Person A] liked by [Person B]
Photos of [Person A] AND [Person B]
photos taken in Paris, France from 2018
photos taken by phone xperia U
Photos of friends of my friends
photos of wedding uploaded by friends of my friends
photos of graduation uploaded by friends of my friends
photos of single friends of my friends uploaded by friends of my friends
# Find new places
Restaurants nearby liked by my friends
[Cuisine] Restaurants liked by my friends of friends in [City]
Hotels nearby liked by my friends of friends
Friends who live (or have lived) in [Place]
Recent photos taken in [Place]
Places in [City] visited by people who live nearby
# Know your followers
People who follow me
People who follow me and like [Page Name]
People who follow me and live in [City]
People who follow me and work at [Company]
People who follow me and were born in [Year]
Friends of friends who follow me
# Find someone
People who work nearby
People who are [Profession Name] (like Doctors, Programmers, etc.)
People who live in [Place]
People who are named [Full or Partial Name]
People who are [Gender] and live in [City] and [Relationship Status]
People who believe in [Religion Name]
People who are N years old
People who are older than X and younger than Y years
People who were born in [Year]
People who work at [Company A] and previously worked at [Company B]
People who live in Paris
People who went to Harvard University
friends of my friends
friends of my friends who are single
friends of my friends who are men interested in men
people who live in new york city who uploaded photos taken in versailles
# But some requests give bad results or false positive
# Alternative is using the Graph Search through the URL
facebook.com/search/str/<search>

# If there are several searchs you can use AND / OR parameters
xxx/intersect 
xxx/union
facebook.com/search/str/<search>/str/secondone/intersect

# People who live in Paris (present and past)
www.facebook.com/search/str/paris/pages-named/residents/present/
www.facebook.com/search/str/paris/pages-named/residents/past/

# People who live in Ile de France now or in France (code)
www.facebook.com/search/str/ile-de-france/pages-named/residents/present/
www.facebook.com/search/str/105604449474183/residents/present/

# Intersect one
# People "Patrick" who live in Toulouse now
www.facebook.com/search/str/patrick/users-named/str/toulouse/pages-named/residents/present/intersect/

# People "Patrick" who live in Toulouse now and Paris in the past
www.facebook.com/search/str/patrick/users-named/str/toulouse/pages-named/residents/present/str/paris/pages-named/residents/past/intersect/

# People who live in Paris and who like the page "afis sciences et pseudo sciences"
www.facebook.com/search/str/afis%20-%20science%20et%20pseudo-sciences/pages-named/likers/str/paris/pages-named/residents/present/intersect/

# Photos containing the keyword "humour"
www.facebook.com/search/str/humour/photos-keyword/

# People "Jeanne" friends of people "Louise"
www.facebook.com/search/str/jeanne/users-named/friends/str/louise/users-named/intersect/

# People who live in Geneva, who like Patrick Bruel's page and Céline Dion's page
www.facebook.com/search/str/geneva/pages-named/residents/present/str/c%C3%A9line%20dion/pages-named/likers/str/patrick%20bruel/pages-named/likers/intersect/

# Searching the keyword "scientifique" posted last month
/www.facebook.com/search/str/scientifique/stories-keyword/last-month/date/stories/intersect/

# Searching someone in Ile de France / France who posted the keyword "scientifique" last month
www.facebook.com/search/str/ile-de-france/pages-named/residents/present/stories/str/scientifique/stories-keyword/stories/intersect/
www.facebook.com/search/str/105604449474183/pages-named/residents/present/stories/str/scientifique/stories-keyword/stories/intersect/

# Searching posts containing "foutaises" or "conneries"
www.facebook.com/search/str/foutaises/stories-keyword/str/conneries/stories-keyword/union/

# Photos posted by French people
www.facebook.com/search/str/105604449474183/residents/present/photos/

# People under 29 who live in Toulouse
www.facebook.com/search/str/toulouse/pages-named/residents/present/29/users-older/intersect/
PreviousInstagramNextTwitter

Last updated 2 years ago

🌐
📡
⏩