| Since this is already out there as a known issue, and concerns Google too, check out: https://www.google.com/search?q=%22wants+to+be+friends+on+Fa... And you'll find at the time of writing 250.000 more results where the "wants to be friends" email with the auto-login link is posted on blogs. Many of these blogs are also hacked, in that they redirect you to Russian dating sites if you visit the homepage. An example of such a blog with password reset email is:
http://papajimummyji.blogspot.com/ An example of a spam-redirecting blog is:
http://demiansyahhh.blogspot.com/ (possibly unsafe) For some more Facebook reset emails see: https://www.google.com/search?q=%22You+recently+asked+to+res... EDIT: Twitter emails are also exposed:
https://www.google.com/search?q=%22Forgot+your+Twitter+passw... Youtube emails:
https://www.google.com/search?q=%22YouTube+sends+email+summa... Twoo emails:
https://www.google.nl/search?q=%22Massive+Media+NV%2C+Emile+... And likely more web services. |