facebook.com (for easyprivacy!!!!!!) [rej]

Here you should report unblocked ads, trackers, social media items, annoyances or leftovers from blocked content.
Locked
bee
Forum Junkie
Forum Junkie
Posts: 172
Joined: Wed Dec 30, 2009 4:58 pm

facebook.com (for easyprivacy!!!!!!) [rej]

Post by bee »

Hi!!!!!!! :D :D

So, i randomly decided to clear the cookies :roll: and go on facebook.com to test something with AdBlock disabled :D :D :D :idea:
If you do the same and you go on http://www.facebook.com/ (no cookies means that you aren't logged in :-? ) you'll see the Sign Up box!!!!!!!!!!!!!! :D :D :idea:
Now, open the list of blockable items, i'm sure that you won't see anything of bad :idea: :idea:
But, if you, select "I am: Select Sex" and you change its value :surprised: :surprised: :-? you'll have this new item showed up!!!!!
http://www.facebook.com/ajax/register/logging.php?__a=1
i wonder what it's useful for, if it's not for tracking purposes :roll: :surprised: :-? :-? :D :D :D :idea:

bye!!!!!!!!!!!!!!!!!! :D :D :D
The bee is more honored than others, not because the bee labors, but because the bee labors for others.
User avatar
Erunno
Emeritus Contributor
Emeritus Contributor
Posts: 1866
Joined: Fri Dec 05, 2008 5:21 pm

Post by Erunno »

This is the XML request which gets send:

for (;;);{"error":0,"errorSummary":"","errorDescription":"","errorIsWarning":false,"silentError":0,"payload":null}

It doesn't look very harmful to me.
Zombie Contributor
Michael Verified
Contributor
Contributor
Posts: 4124
Joined: Sun Aug 23, 2009 8:08 pm

Post by Michael Verified »

I agree with Erunno; at the very worst the item is a "harmless" tracker not suitable for EasyPrivacy.
bee
Forum Junkie
Forum Junkie
Posts: 172
Joined: Wed Dec 30, 2009 4:58 pm

Post by bee »

Erunno wrote:This is the XML request which gets send:
actually :-? what you wrote is what the XML request receives as answer :idea: :idea: :biggrin: :D not what it sends :idea:
Erunno wrote:It doesn't look very harmful to me.
I ain't very sure :idea: :idea: Install https://addons.mozilla.org/en-US/firefox/addon/3829/ to see what your browser sends to facebook :D :D :D :idea:
Michael is right it's a tracking thing!!, even if maybe it's not okay for EasyPrivacy; but it's for sure a tracking applet!!!!!!!!!!!!!!!!! :D :D :D :idea:
POST /ajax/register/logging.php?__a=1 HTTP/1.1
Host: http://www.facebook.com
User-Agent: Mozilla/5.0 (X11; U; Linux ........
Accept-Encoding: gzip,deflate
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Referer: http://www.facebook.com/
Content-Length: 103
Cookie: datr=cookies!!!!!!!!!!!!!!!!!!!!
Pragma: no-cache
Cache-Control: no-cache

action=form_focus&reg_instance=12312312313-1f313f21f313aaabcd1321313abc13132abc13bcd&fb_aaaa
I just removed my personal info :-? :D :D But that's the query sent to facebook, and the line on the bottom is the invisible POST query!!!!!!!!!!!!!!!!!! :D :D :D :idea:
They're indeed tracking everything you do :-? :idea: :idea: action=form_focus and reg_instance= is probably the ID they've assigned to you :surprised: :surprised: :idea: :biggrin: :D

bye!!!!!!!!!!!!!!!!!!! :D :D :D
The bee is more honored than others, not because the bee labors, but because the bee labors for others.
Guest
Guest

Post by Guest »

Please stop using massive smilies and exclamation marks, the text is hard to read with all that images.

On-topic:
Facebook external scripts(e.g. "like"-button, "facebook connect") should be added to EasyPrivacy.
Michael Verified
Contributor
Contributor
Posts: 4124
Joined: Sun Aug 23, 2009 8:08 pm

Post by Michael Verified »

The issue of blocking Facebook has already been discussed and rejected at http://forums.lanik.us/viewtopic.php?t=6430.
User avatar
Hubird Verified
Adversity Author
Adversity Author
Posts: 1768
Joined: Sun Sep 30, 2007 4:31 am
Location: Australia

Post by Hubird Verified »

I am a bit worried about blocking XML files but bee seems to have done the research. I don't use facebook and don't want to break anything, has anyone tested the site while blocking this file ?
bee
Forum Junkie
Forum Junkie
Posts: 172
Joined: Wed Dec 30, 2009 4:58 pm

Post by bee »

Hi!!!!!!!!!! :D

Yeah, it works :idea: , if you go there to register one account as i did, it'll then say that it sent you the confirmation email :D :D :idea: of course my registration didn't went through because i entered as email something like :arrow: :arrow: "yakou.yojae@realprovider.com" (the username is fake :idea: :idea: :D :biggrin: )

Also :idea: :idea: the long number sent to the logging.php page, is the unique ID that facebook assigns to you!!!!!!! :D :D if you look at the HTML code of the registration page you can find it in the HTML SUBMIT FORM code!!!!!!!!! :D :D :surprised: :idea:
<input type="hidden" id="reg_instance" name="reg_instance" value=" :-? _BIG_NUMBER_ :surprised: " autocomplete="off" />
I used this filter to block that tracking request :D :D :idea: :arrow:

Code: Select all

facebook.com/ajax/register/logging.php
bye!!!!!!!!!!!!!!!!!! :D :D :D
The bee is more honored than others, not because the bee labors, but because the bee labors for others.
User avatar
Erunno
Emeritus Contributor
Emeritus Contributor
Posts: 1866
Joined: Fri Dec 05, 2008 5:21 pm

Post by Erunno »

The cookies will be sent anyway. Go to facebook.com, leave it, go to facebook.com again et voilà: Cookies are sent without the logging.php thingie. And I'm hesitant to block Facebook stuff since it's a very popular service and we can expect a large mob with torches and pitch forks heading our way should we in any way break it. :P
Zombie Contributor
Locked