Hacker News new | past | comments | ask | show | jobs | submit login

Yes, I just found out yesterday that setting your referrer to facebook.com/l.php allows you to reliably bypass the paywall.

E.g. http://facebook.com/l.php?u=http://www.wsj.com/articles/poli...




Thanks, that does work. Though I still feel a little funny about jumping through a bunch of weird hoops to read news articles.


Wow, I don't even have a facebook account and that works. That feels like some XSS waiting to happen :/


It's an open redirect, not XSS. It's a matter of debate whether an open redirect is a vulnerability or not.


In case anyone's still here, I made a bookmarklet for it:

javascript:location.href='http://facebook.com/l.php?u='+encodeURIComponent(location.hr...

Make a bookmark with that, call it I'm from Facebook or something, and go to it when you hit a paywall.


This trick is the only thing that seems to bypass WSJ paywall now




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: