Tag Archive: Instagram

XSS on Facebook-Instagram CDN Server bypassing signature protection.

Facebook and Instagram all photos/videos are stored on their CDN Server “*.fbcdn.net” and “*.cdninstagram.com” and they served via various sub-domains. Those all of the photos/videos on CDN Server contain a hash in the URL (various parameters ‘oh’ and ‘oe’ etc), which causes an error to be thrown if we modify the file extension.(eg. “.jpg” to […]

Read More →