Facebook Pwn tool takes profile info, helps social engineers
A group of security researchers based in Egypt have created a tool that will make social engineering easier because it automates the collection of hidden Facebook profile data that is otherwise only accessible to friends in a user's network.
The cross-platform, Java-based tool is called "Facebook Pwn" and is described by those who developed it as a "Facebook profile dumper."
"(The tool) sends friend requests to a list of Facebook profiles, and polls for the acceptance notification. Once the victim accepts the invitation, it dumps all their information, photos and friend list to a local folder," the description notes. In a typical scenario described by the researchers, the hacker starts by gathering information from a user profile by creating a new blank account. Then, using what they call a "friending plugin" one can add all the friends of the victim. This will ensure you have some common friends with the victim, the researchers note.