Hacker News new | ask | show | jobs
Interactive example of how Facebook leaked access tokens (history.adversary.io)
50 points by Glitch-is 2800 days ago
4 comments

I'm getting errors whenever I visit, but was able to load the "mission" page earlier and see the format (though it also had errors; the center page didn't load at all). Seems like a great idea for explaining these sorts of things!
The url is incorrect above, it should be https://history.adversary.io/missions/facebook, the above url includes the "/birthday" which causes the 400
The link you posted redirects to https://history.adversary.io/missions/facebook/birthday. It seems to not be working right now.
It doesn't seem to be caused by that, I've seen the error with and without the /birthday suffix. It looks to be related to missing data from one of the GraphQL responses.
It should work now
We also wrote an article about the attack. Check it out if you're interested https://blog.adversary.io/facebook-hack/
I can see the messages from Minea as Lark, but when I click "SUBMIT FLAG" I get "Invalid Flag Submission"
It should work now
There really isn't any technical details about this at all from what I read in the article or using the interactive tool. If this is a SaaS product for developers, wouldn't the actual "deep dive" I expected contain that? It's to high level and doesn't offer more value than some general blog telling me a few basics w/ some links to better content.

Did I miss something?

I think the interactive tool is a cool idea none the less.

the link not working

also shows a security warning in ff