25 Jan
2012
This blog post is targetted to every one using Facebook. Yes, I am putting my privacy as well as of many others at stake over here but people NEED to be informed about this. Also, I am aware that my method can use this method to stalk other people and steal photo. But what the heck, the information is right up there, on the Internet.
Several "Social Media" fanatics have been using Facebook and Twitter to communicate with strangers and friends. These people, especially girls, are least aware about privacy and security concerns related to these social networks.
I have pleaded several individuals to change the file names of the images they upload as Twitter Avatar or display picture. Here's the actual way how any nefarious nuisance creator/stalkers can reach your Facebook profile and steal information or harrass you by sending Friendship request.
Typical Twitter Display Photo URL: (dummy URL)
https://twimg0-a.akamaihd.net/profile_images/1750068488/312204_10150282077977314_502877313_7927464_1213368742_n.jpg
This is how a typical Twitter Avatar or Display Photo URL looks like. Note the numbers (312204_10150282077977314_502877313_7927464_1213368742_n) that precede the .jpg file name. It is the file name of the image you must have saved from somewhere (Facebook).
Typical Facebook Image URL:
https://fbcdn-photos-a.akamaihd.net/hphotos-ak-snc7/312204_10150282077977314_502877313_7927464_1213368742_n.jpg
Note the similarity on the numbers before (312204_10150282077977314_502877313_7927464_1213368742_n) .jpg in this URL?
This directly hints that the Twitter display picture is indeed take from a Facebook Profile. But whose Facebook profile?
In the following file name: 312204_10150282077977314_502877313_7927464_1213368742_n.jpg, the number after the second underscore is the Profile ID of the user.
In this case: the Profile ID is 502877313.
Now if you simply put that number in Facebook Profile URL, you get - https://www.facebook.com/profile.php?id=502877313
Yes, that is my Facebook Profile.
Hereby, I plead all those who have read to AVOID using the same file name for the photos downloaded from Facebook. Change the file name wherever you upload the photos again.