I have a customer who got his Facebook account hacked.
The hacker changed both the recovery phone number and the password.
Facebook sends a six digit recovery text to the HACKER not my customer.
Can't change the password as the old one is required.
The customer can automatically log into face book through Firefox.
Problem: Firefox's password manager shows the wrong password for Facebook.
I tried installing Brave Browser and importing the Firefox profile. It got the same bad password.
The customer can not even delete his account as facebook asks for the password to verify.
AAAAAAAAAAAAAAAAHHHHHHHHHHHHHHHHHHH!!!!!!!!!!!!!!
Where did Facebook rat pack the actual password in Firefox?
-T
Didn't find your answer? Ask the community — no account required.
T
T
Sorry. That was suppose to go to the Firefox group. Me fumble fingers.
I
invalid unparseable
Is there a Firefox group? I see one but it appears French and nothing is there. I use Firefox and know you can remove or change passwords. Also use Facebook and it can be messy with hackers getting friend requests from friends you already have and even those that died.
T
T
alt.comp.software.firefox
Normally yes. The password in Firefox's password manager is the wrong password. The right one is squirreled away some where hidden.
And the hacker changed the recovery eMail address and the text address too, so forgot password does not work.
T
trader_4
Something is wrong here. FB or other websites don't put passwords into browser PWD managers, the browsers do that when you enter the PWD yourself, if you want it done and say yes. The only way I can conceive of this happening would be if Firefox manages passwords across multiple devices, like Google does, which they probably do and the hacker has logged into Firefox as your customer and has control of that too.
M
micky
That seems strange.
A lot of sites have more than one login screen. The one that shows up when you enter
formatting link
, the one that shows up when you enter an invalid userid and a different screen comes back, and others. Normally Firefox password manager should all have the same userid and password for all of them, or most of them and blankness for the others.
Has he checked all such entries to make sure they all have the wrong password.****
Yes, iiuc you can synchronize Firefox from one device to others. I don't do that because I like having differences, but they offer it.
It sounds like an inside job. An employee or a wife. I wonder if anything malicious has been done, yet.
****Conceivably he's hacked himself. One time when he forgot or kept mistyping his password and they forced him to enter a new one, and he forgot the whole episode. (Does he get drunk a lot?) But if he can log in automatically from Firefox, then Firefox password manager has the new password.
A good add-on for Firefox is Password Toggler - view typed passwords .
For most, but not all, pages it will display an "eye" and let you see what password you typed in or FF filled in. Saves a lot of time. Helps let you know which is wrong, userid or pswd. It would be helpful here.
Anyone with access to one's computer can go into FF password manager (about:logins but easier to get there through a menu) and see what the password is, then go change it. I suppose certain malware would enable a stranger to do this from the outside, but I have not heard of it. A keylogger would be enough. Does the customer use AV software? Still, I don't save my bank or credit card userid or password within Firefox. Have a list in an obscure place that I think no automated method can find, and I don't think anyone is targeting me specifically, that is, searching my files by hand.
I regret taking so seriously at first some of the password advice. I should have used the same login and password for all the things that don't matter, like my subscription to Hiking News or ToyotaNation. Then I would know that one by heart for when I change computers or want to use the phone.
T
T
Hi Micky,
The computer in questions did show signs of being controlled by someone else for a while. I presume it was the hacker. Could have been an employee.
His wife had full access to the account, which was advertising his business. And she was probably responsible for most of the content. I have know both of them for years. They are salt of the earth.
The hackers changed the recovery eMail AND the recovery text cell phone, so "forgot password" and change password did not work as the six digit code was sent to the hacker not the customer. And change password required the password the hacker was using.
The customer accesses Facebook from several other devices and got knocked off all but this one computer. And this one computer, only Firefox autologged in.
And neither I nor the customer could find how to contact Facebook's tech support.
The customer had also used very light weight, in the dictionary, passwords, so it would have been very easy to hack him. I told him how to come up with something unhackable.
-T
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required
Report Content
You are reporting this content to the moderators. They will look at it
ASAP.