However, one California-based hacker tried something similar.
The social networking giant uses an algorithm that generates a random 6-digit passcode ?
= 1,000,000 possible combinations.
This means that more than two people have the same passcode.
The URL then automatically changes the ID to the username.
This data was compiled into a JSON by Singh.
He used a multithreaded script to simulate user behaviour when a passcode is required.
The script requests a passcode to every user in the JSON file created earlier.
Then the scripts were run to make the requests.
source: www.techworm.net