Sign in to follow this  
Eminem

HOW TO ENABLE FACEBOOK WHITE HAT RESEARCHER SETTING

Recommended Posts

Facebook have implemented a white hat secuirty testing setting that allows its users to test security over various Facebook services.

 

 

 

[hide]

 

Facebook will knowingly break its Certificate Pinning mechanism for its users that use white hat settings. Pinning is used to improve security of a website that uses SSL. Pinning allows websites to allow or disallow a user by searching for a specific cryptographic identity. SSL Certificate Pinning techniques are often used to defend against sniffing attacks.

 

 

Whitehat Settings can be enabled by going to Facebook’s main app however Facebook Messenger instant messaging client and Instagram app is only supported for Android.

 

 

 

Facebook White hat settings has built-in proxy for that can be used for API interactions. Facebook White Hat settings have included a feature that can disable TLS 1.3 support.

 

 

 

To enable Facebook White Hat researcher settings go to

 

 

 

 

 

 

facebook-whitehat.png?resize=800%2C450&ssl=1

 

Image shows Facebook White Hat Researcher settings.

 

 

Once white hat researcher settings are enabled, a Whitehat Settings button will show up in each of the applications selected.

 

From the white hat researcher settings we can enable user installed CAs for your Facebook account and Facebook white hat test account.

 

 

 

 

Facebook Android App White Hat Settings can be found under Settings & Privacy.

 

 

 

facebookwhitehat.jpg?resize=138%2C300&ssl=1

 

whitehat2.jpg?resize=138%2C300&ssl=1

 

Facebook Messenger App White Hat Settings can be found by clicking on your display picture and scrolling down to Internal.

 

Screenshot_20190327_033127_com.facebook.orca_.jpg?resize=138%2C300&ssl=1

Screenshot_20190327_033318_com.facebook.orca_.jpg?resize=138%2C300&ssl=1

 

It’s easy and best practice to turn White Hat Researcher settings off when we are not testing any Facebook applications.

 

[/hide]

Share this post


Link to post
Share on other sites

You can Contact them at a

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Sign in to follow this