
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
@sugarcube/plugin-facebook
Advanced tools
@sugarcube/plugin-facebook
Query the Facebook GraphAPI.
npm install --save @sugarcube/plugin-facebook
It requires you to register your app.
You'll need the app_id
and the app_secret
.
facebook_api_user
(DEPRECATED)Fetch data about a user. It uses facebook_user
as query type.
sugarcube -Q facebook_user:<user_id> \
-p facebook_api_user \
--facebook.app_id <app_id> \
--facebook.app_secret <app_secret>
You need the userid
, the username won't work. To get it:
CTRL-f
to search through the source and search for
user.php?id=
. This is your user id.Configuration
facebook_api_page
(DEPRECATED)Fetch data about a Facebook page. It uses facebook_page
as query type.
sugarcube -Q facebook_page:<page_name> \
-p facebook_api_page \
--facebook.app_id <app_id> \
--facebook.app_secret <app_secret>
Configuration
facebook_api_feed
(DEPRECATED)Fetch the feed of a Facebook page. It uses facebook_page
as query type. This
works currently for pages only.
sugarcube -Q facebook_id:filmsforaction \
-p facebook_api_feed \
--facebook.app_id <app_id> \
--facebook.app_secret <app_secret>
Configuration Options:
The following example fetches the feed of facebook pages, downloads all
images, fetches videos using youtube-dl
, takes screenshots of the
entries and exports a CSV file. One of the pages fails because it doesn't
exist. The facebook_api_feed
plugin ignores missing pages, and continues
with the rest of the pipeline.
$(npm bin)/sugarcube -c configs/facebook.json \
-Q facebook_page:BATH5,facebook_page:MoqawamaSourria \
-p
facebook_api_feed,http_get,http_screenshot,media_youtubedl,csv_export
\
--csv.filename data.csv \
--http.data_dir data \
--http.headless true \
--http.get_types image \
--media.youtubedl_cmd youtube-dl \
--media.download_format mp4 \
--media.data_dir data \
-d
FAQs
Fetch data from facebook for sugarcube.
We found that @sugarcube/plugin-facebook demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.