How To: 4 Ways to Crack a Facebook Password & How to Protect Yourself from Them

4 Ways to Crack a Facebook Password & How to Protect Yourself from Them

Despite the security concerns that have plagued Facebook for years, most people are sticking around and new members keep on joining. This has led Facebook to break records numbers with over 1.94 billion monthly active users, as of March 2017 — and around 1.28 billion daily active users.

We share our lives on Facebook. We share our birthdays and our anniversaries. We share our vacation plans and locations. We share the births of our sons and the deaths of our fathers. We share our most cherished moments and our most painful thoughts. We divulge every aspect of our lives. Clinical psychologists have written entire books detailing the surprisingly extensive impact Facebook has on our emotions and relationships.

But we sometimes forget who's watching.

We use Facebook as a tool to connect, but there are those people who use that connectivity for malicious purposes. We reveal what others can use against us. They know when we're not home and for how long we're gone. They know the answers to our security questions. People can practically steal our identities — and that's just with the visible information we purposely give away through our public Facebook profile.

Image via Digital Trends

The scariest part is that as we get more comfortable with advances in technology, we actually become more susceptible to hacking. As if we haven't already done enough to aid hackers in their quest for our data by sharing publicly, those in the know can get into our emails and Facebook accounts to steal every other part of our lives that we intended to keep away from prying eyes.

In fact, you don't even have to be a professional hacker to get into someone's Facebook account.

It can be as easy as running Firesheep on your computer for a few minutes. In fact, Facebook actually allows people to get into someone else's Facebook account without knowing their password. All you have to do is choose three friends to send a code to. You type in the three codes, and voilà — you're into the account. It's as easy as that.

In this article I'll show you these, and a couple other ways that hackers (and even regular folks) can hack into someone's Facebook account. But don't worry, I'll also show you how to prevent it from happening to you.

Method 1: Reset the Password

The easiest way to "hack" into someone's Facebook is through resetting the password. This could be easier done by people who are friends with the person they're trying to hack.

  • The first step would be to get your friend's Facebook email login. If you don't already know it, try looking on their Facebook page in the Contact Info section. Still stuck? Hackers use scraping tools like TheHarvester to mine for email addresses, so check out our guide here to find a user's email that you don't already know.
  • Next, click on Forgotten your password? and type in the victim's email. Their account should come up. Click This is my account.
  • It will ask if you would like to reset the password via the victim's emails. This doesn't help, so press No longer have access to these?
  • It will now ask How can we reach you? Type in an email that you have that also isn't linked to any other Facebook account.
  • It will now ask you a question. If you're close friends with the victim, that's great. If you don't know too much about them, make an educated guess. If you figure it out, you can change the password. Now you have to wait 24 hours to login to their account.
  • If you don't figure out the question, you can click on Recover your account with help from friends. This allows you to choose between three and five friends.
  • It will send them passwords, which you may ask them for, and then type into the next page. You can either create three to five fake Facebook accounts and add your friend (especially if they just add anyone), or you can choose three to five close friends of yours that would be willing to give you the password.

How to Protect Yourself

  • Use an email address specifically for your Facebook and don't put that email address on your profile.
  • When choosing a security question and answer, make it difficult. Make it so that no one can figure it out by simply going through your Facebook. No pet names, no anniversaries — not even third grade teacher's names. It's as easy as looking through a yearbook.
  • Learn about recovering your account from friends. You can select the three friends you want the password sent to. That way you can protect yourself from a friend and other mutual friends ganging up on you to get into your account.

Method 2: Use a Keylogger

Software Keylogger

A software keylogger is a program that can record each stroke on the keyboard that the user makes, most often without their knowledge. The software has to be downloaded manually on the victim's computer. It will automatically start capturing keystrokes as soon as the computer is turned on and remain undetected in the background. The software can be programmed to send you a summary of all the keystrokes via email.

Null Byte features an excellent guide on how to get a keylogger on a target computer to get you started. If this isn't what you're looking for, you can search for free keyloggers or try coding a basic keylogger yourself in C++.

Hardware Keylogger

These work the same way as the software keylogger, except that a USB drive with the software needs to be connected to the victim's computer. The USB drive will save a summary of the keystrokes, so it's as simple as plugging it to your own computer and extracting the data.

There are several options available for hardware keyloggers. Wired keyloggers like the Keyllama can be attached to the victim's computer to save keystrokes and works on any operating system — provided you have physical access to retrieve the device later. If you're looking to swipe the passwords remotely, you can invest in a premium Wi-Fi enabled keylogger which can email captured keystrokes or be accessed remotely over Wi-Fi.

How to Protect Yourself

  • Use a firewall. Keyloggers usually send information through the internet, so a firewall will monitor your computer's online activity and sniff out anything suspicious.
  • Install a password manager. Keyloggers can't steal what you don't type. Password mangers automatically fill out important forms without you having to type anything in.
  • Update your software. Once a company knows of any exploits in their software, they work on an update. Stay behind and you could be susceptible.
  • Change passwords. If you still don't feel protected, you can change your password bi-weekly. It may seem drastic, but it renders any information a hacker stole useless.

Method 3: Phishing

This option is much more difficult than the rest, but it is also the most common method to hack someone's account. The most popular type of phishing involves creating a fake login page. The page can be sent via email to your victim and will look exactly like the Facebook login page. If the victim logs in, the information will be sent to you instead of to Facebook. This process is difficult because you will need to create a web hosting account and a fake login page.

The easiest way to do this would be to follow our guide on how to clone a website to make an exact copy of the facebook login page. Then you'll just need to tweak the submit form to copy / store / email the login details a victim enters. If you need help with the exact steps, there are detailed instructions available by Alex Long here on Null Byte. Users are very careful now with logging into Facebook through other links, though, and email phishing filters are getting better every day, so that only adds to this already difficult process. But, it's still possible, especially if you clone the entire Facebook website.

How to Protect Yourself

  • Don't click on links through email. If an email tells you to login to Facebook through a link, be wary. First check the URL (Here's a great guide on what to look out for). If you're still doubtful, go directly to the main website and login the way you usually do.
  • Phishing isn't only done through email. It can be any link on any website / chat room / text message / etc. Even ads that pop up can be malicious. Don't click on any sketchy looking links that ask for your information.
  • Use anti-virus & web security software, like Norton or McAfee.

Method 4: Man in the Middle Attack

If you can get close to your target, you can trick them into connecting to a fake Wi-Fi network to steal credentials via a Man In The Middle (MITM) attack. Tools like the Wi-Fi Pumpkin make creating a fake Wi-Fi network is as easy as sticking a $16 Wireless Network Adapter on the $35 Raspberry Pi and getting close to your target. Once the victim connects to your fake network, you can inspect the traffic or route them to fake login pages. You can even set it to only replace certain pages and leave other pages alone.

This little computer can create an evil AP - a cloned wireless network to trick the user into connecting so you can listen in on their traffic. Image by SADMIN/Null Byte

How to Protect Yourself

  • Don't connect to any open (unencrypted) Wi-Fi Networks.
  • Especially don't connect to any Wi-Fi networks that are out of place. Why might you see a "Google Starbucks" when there's no Starbucks for miles? Because hackers know your phone or computer will automatically connect to it if you have used a network with the same name before.
  • If you have trouble connecting to your Wi-Fi, look at your list of nearby networks to see if there are any copies of your network name nearby.
  • If your router asks you to enter the password for a firmware update to enable the internet or shows you a page with major spelling or grammar errors, it is likely you're connected to a fake hotspot and someone nearby is trying to steal your credentials.

A Couple More Facebook Hacks

For those with a bit more technical skill, check out the Same Origin Policy Facebook hack and the somewhat easier, Facebook Password Extractor. We will continue add more Facebook hacks in the near future, so keep coming back here.

How to Protect Yourself

  • On Facebook, go to your Account Settings and check under Security. Make sure Secure Browsing is enabled. Firesheep can't sniff out cookies over encrypted connections like HTTPS, so try to steer away from HTTP.
  • Full time SSL. Use Firefox add-ons such as HTTPS-Everywhere or Force-TLS.
  • Log off a website when you're done. Firesheep can't stay logged in to your account if you log off.
  • Use only trustworthy Wi-Fi networks. A hacker can be sitting across from you at Starbucks and looking through your email without you knowing it.
  • Use a VPN. These protect against any sidejacking from the same WiFi network, no matter what website you're on as all your network traffic will be encrypted all the way to your VPN provider.

Protecting Yourself: Less Is More

Social networking websites are great ways to stay connected with old friends and meet new people. Creating an event, sending a birthday greeting and telling your parents you love them are all a couple of clicks away.

Facebook isn't something you need to steer away from, but you do need to be aware of your surroundings and make smart decisions about what you put up on your profile. The less information you give out on Facebook for everyone to see, the more difficult you make it for hackers.

If your Facebook account ever gets hacked, check out our guide on getting your hacked Facebook account back for information on restoring your account.

Bonus: If you're interested in who's checking you out, there are some ways you can (kindof) track who's viewed your Facebook profile.

More Password-Hacking Guides

For more info on cracking passwords, check out our guides on hacking Linux passwords, hacking Windows passwords, and our super-easy beginner's guide on hacking Wi-Fi passwords (or for newer wireless routers, how to crack WPA2-PSK wifi passwords).

Just updated your iPhone? You'll find new emoji, enhanced security, podcast transcripts, Apple Cash virtual numbers, and other useful features. There are even new additions hidden within Safari. Find out what's new and changed on your iPhone with the iOS 17.4 update.

106 Comments

how to access to friend whi has blocked me

Your best bet would be to create another profile and try and add them that way, but I wouldn't suggest doing that if they want their privacy.

Instead of putting in their email account, does it work the same for their phone number since FB allows you to log in with your number also?

I was wondering the same thing. Did u ever get an answer or to get I to work?

On Facebook, go to your Account Settings and check under Security. Make sure Secure Browsing is enabled. Firesheep can't sniff out cookies over encrypted connections like HTTPS, so try to steer away from HTTP.

*Contact the best hackers in the world a simple whatsapp to +91-851OO49O81...*

Full time SSL. Use Firefox add-ons such as HTTPS-Everywhere or Force-TLS.
Log off a website when you're done. Firesheep can't stay logged in to your account if you log off.

Use only trustworthy Wi-Fi networks. A hacker can be sitting across from you at Starbucks and looking through your email without you knowing it.

Use a VPN. These protect against any sidejacking from the same WiFi network, no matter what website you're on as all your network traffic will be encrypted all the way to your VPN provider.

Everybody please stop commenting here about "hacking into you'r friends facebook." We're not going to help you or something. Just google it and you'll find out how it works. you could also use My post if that helps you further, but STOP posting here. This is a comment section not a asking section!

i see you, haha, don't blame a noon or lamer. It not their false, huhu.

I also see you on youtube, anonymous. Well, with pleasure, I am Htag, from anon, nice to meet you. Also, we are sharing and caring about other, may I know your facebook name or any contact email. It will be pleasure.

OMG!!! Thank God sum one said sumthing about this....itz awful to be seeing people talking 'bout hacking someone's page on ANY site...thank-you sooo much for speaking up...TH3 SKY FOX...

you need the help of professionals as hacking cannot be carrued outbwithouthacking knowledge

Great!
Thank you so much.

hey i wannit to ask that when he said that you have to type the email you have but it should not be linked to any other facebook account than does that mean we should type in the victim's email ???

The Firesheep is no longer supporting my Fireox 21.0, this version seems to be new over. :(

Firesheep only supports firefox 3.6...

guys i need your help can we just talked by PM on the ways/how i can do it.. my cousin need help for her account that she forgot ..hehehe

how can i get my boyfriend facebook password?

very easy,you ask him "what your is fb password is?"

you can simply phish the password

nice one man
yet another great post don't stop doing what your doing

and to all the people who want to know how to hack fb accounts its right there in black and white. If that is to complicated most of you are asking to hack your friends let them use your computer with a key logger or set your browser to remember passwords simple ;)

i did this process (3 truested friends) not my mistake is that that i couldn't receive that time! but now i hav that 3 codes but pro is that now the entering codes page is noe opening! bcz we need codes that tym! now i m realy confuse! n hope so we w'll help me as wel u can do it! plz i realy want my account back :/ :'(

So nice post, i tried the first method on my account but is doesnt work, but in my brother account it works......
In my account doesnt appear "How can we reach you?"
Only see this:

I supose that is the configuration of my account.

Well, i enjoy so much, nice post, and nice web, see ya!!!

Hey, when i tried doing the 1st one it was asking me to answer the question which i dont the amswer but there were no options below given to send these codes to ur friends how do you do that?

Any cookie retriever in google chrome :/

Ohh... interesting. Thanks

Using the first method, the person you are trying to hack shouldn't receive an email saying their password has been reset listing the IP address from which i was changed right?

Why would ANYONE want to hack into a "friend's" page? That is just wrong.

YOU'RE RIGHT...I don't understand why it is going on....it makes no sense at all...itz hard for me to fathom what people are doing to each other nowadays...

Dude shut up quit bitching and complaining how people want to hack into their friend's account if they want to do that then it's their business if you don't think it's right then why the hell are you on this page? I mean no one forced you to be on this page right

I think my mates face book has been hacked of a ex .in the top left their is like a blue barcode and when she has pressed onto it it has taken her to somet witch says something about a tablet .but she's on her mobile .just really strange things are happening to her account

there are virus errors in every keylogger software

is really helpful........... nice one

anyone wants to help me out here?? i was wondering what if i try to hack a profile and facebook notify that person that someone is trying to hack his profile from a specific country. he would automatically understand that its me :(

Yes it does. It will post a warning saying someone is trying to log in from x place at x time.

no problem.
just use a proxy server and enjoy.

Use real hide ip software ...easy peasy...

Hey so when you get to the part about soliciting friends to provide the key information bits, will it be asking me for my friends or assuming that I am really the account owner it will be showing me a list of their friends? Which I would then have to manipulate into providing me the pass phrases somehow? How would I get the three friends to tell me the info without giving away that I am not the account owner? Thanks!

i want to hack my gf account...............
i think keylogger is best option for hack friends facebook id

I believe that after 24 h if you do not complete the process the link expires. I am referring to the first method of getting access of someone's pass so you have to keep an eye on that to make sure it does not expire the link.

The first method is removed from facebook, did someone know how to do it yet?

Gain physical access to victims pc and do a keylogger process. It might work if victim is a jackass...

Yeah i tried doing it but it was asking m to answer the question which i dont know bit as said there were no select friends to sedm tje code waa available: /

The firesheep doesn't work anymore.. I read it on other place that it's making a big news and exposed.

Is is possible to perform hacks if I have a chromebook with chrome OS?

Keyloggers are the best way to do it,if you know how to get them into the victims PC..

Here i am unable to proceed to next step bcoz it not shows Ask help from friends!! Please help me..!! I dont know his securiy question answer

hi i have victim ip address,mac address ,even his last pwd but i want to know his pwd dont wnna to reset it.

You can hack into his system easily if you have his ip address.... (Note: ip addresses keeps on changing and are not permanent ) gain physical access over victims pc by using Backtrack. .. you can also use cmd for this purpose....

Are commercial SW keyloggers really undetectable?

They are detectable and now-a-days people are not that dumb they can easily figure out about this hack...

Wow that is kinda scary... But good thing i don't have any friends then.. :) :)

I tried phishing and followed all the steps. I even made the phishing url, but when i sent it to my friend and he opened it, the browser itself told him that it is a phishing site or malfunction detected. What should i do to stop thid from happening.

yeah u can stop it but that method doesnt worth it . u can create a phishing page by going on 000webhost.com .

Same happened to me when i tried phishing attack a year earlier.... so i am also trying to find a latest method to hack into their accounts...Firesheep doesn't work correct even on 3.6v ... Keylogger shit is not good so are the other methods... Hack is easy if you can have a physical access to the victims pc...

if u have any problem related to phishing u can talk to me personally on message ..

AB

You are great so much information that page have thanks

That sound's interesting but now days its really complected and restricted from facebook...

Interesting read... even though i deleted my fb page ages ago..

Waaoh. I realy liked this Hacking for its like rats game, thuo i have not yet tried. Let me trie and come back to you Lol

"Recover your account with help from friends" this option is not coming.
So what should I do now?

You should bark like a dog

Hi, Can you help me to hack facebook passwords

i think the best way to hack is creating a fake web page it was the the only way wich worked with me

Some people know my fb passwords and he change it. I no more able acces to my fb now and my email Password I doesent reamber.my old number no more in used.in this case how I can reset my fb password. Can any 1 help out.

Were you ever able to recover your password or reset it or whatever? Im trying to find out how to do the same thing

I dont have the email address but I do have the phone number. Is there anyway to hack into the facebook account using the phone number?

i dont know why its coming up like that

hey how can I hack facebook please tell me

Facebook actually allows people to get into someone else's Facebook account without knowing their password.

is this right ....?????

Is, that right? Do u know how it's done?

sir the problem in keylogger is that when i install keylogger antivirus in system detects it and delete the files . if there is any keylogger that is not detected by antivirus plz tell me.......

Firesheep only works with http, yeah?
So not really useful when FB is https nowadays. Or am I missing something?

I've tried all of this and I don't have the skill level to do it. I also don't have the money to hire someone to do it for me. Is there an easier way or someone that can do it for the sole purpose of helping another person out?

Wow! Really great post share. Thank you very much for this post share, I really use the full post.

hi guys,

this is srijith from india.Guys someone hacked my facebook account by using phishing method. i don't know how to recover my account. he also hacked my facebook linked all sites and accounts also, pls grant me and pls help me out.

My facebook account was hacked about a month ago & the hacker added their email, changed the phone number, and added 2 step verification. I have reset the password but cannot get pass the code generator. I tried to go through the Facebook Help Center but I cannot even submit an ID recovery. Please, I need help accessing this Facebook account. Any advice or help is appreciated. Can I regain access without spending money on software?

Share Your Thoughts

  • Hot
  • Latest