27th Jun 2009
Watch albums of strangers on Facebook!
Facebook has always been touted to have strong privacy controls. To most extent it is true and it is much better than most of the other social networks. But as a biggest social network they do have loopholes which can be easily exploitable by atleast developers like us.
Today I am going to talk about one such exploit:
How to view albums of people who are not your friends?
So when we search for interesting people on Facebook most of the time you will find their profile having restrictions. Mostly you will be able to see their profile photo and will be able to send message to them. So to see their full profile or albums we have to send “add friend” request and if they approve then and then only we can see their photos and profile.
But here is one way to bypass this:
First you have to add developers application in Facebook which can be added from following link:
Link: http://www.facebook.com/developers/?ref=sb
Then go to this link
http://developers.facebook.com/tools.php
It will open below page and choose you response formate and also method = photos.getalbum as shown in below image.

So after that enter facebook user id whose photos you want to see, in “uid text box” as shown in below image and then press “call method button”.
Get the facebook id from the address bar/url bar or find the “add as a friend” link in the web page and move your mouse cursor over it and you will get facebook id in the status bar as shown in image.

And you will get details of all the albums of that user if he or she have albums as shown in below image in right side box.
Just you have to copy link content from right box and paste it to another browser or tab and press enter and then you can see all photos from that album without adding the user as a friend.

Note: I have changed all the ids they are not real.
I hope with the help of this article and community, facebook will notice this bug and will resolve it.
So enjoy peeking on stranger’s albums. 
Update: It seems that Facebook has resolved this bug now.
Facebook has always been touted to have strong privacy controls. To most extent it is true and it is much better than most of the other social networks. But as a biggest social network they do have loopholes which can be easily exploitable by atleast developers like us.
Today I am going to talk about one such exploit:
How to view albums of people who are not your friends?
So when we search for interesting people on Facebook most of the time you will find their profile having restrictions. Mostly you will be able to see their profile photo and will be able to send message to them. So to see their full profile or albums we have to send “add friend” request and if they approve then and then only we can see their photos and profile.
But here is one way to bypass this:
First you have to add developers application in Facebook which can be added from following link:
Link: http://www.facebook.com/developers/?ref=sb
Then go to this link
http://developers.facebook.com/tools.php
It will open below page and choose you response formate and also method = photos.getalbum as shown in below image.

So after that enter facebook user id whose photos you want to see, in “uid text box” as shown in below image and then press “call method button”.
Get the facebook id from the address bar/url bar or find the “add as a friend” link in the web page and move your mouse cursor over it and you will get facebook id in the status bar as shown in image.
And you will get details of all the albums of that user if he or she have albums as shown in below image in right side box.
Just you have to copy link content from right box and paste it to another browser or tab and press enter and then you can see all photos from that album without adding the user as a friend.

Note: I have changed all the ids they are not real.
I hope with the help of this article and community, facebook will notice this bug and will resolve it.
So enjoy peeking on stranger’s albums. ![]()
Update: It seems that Facebook has resolved this bug now.
Posted by divyang.shah under
Code, Security, Uncategorized
7 Comments »






