Skip to content

Repository files navigation

SpikedVodka - Automate FB Group Request Handling

If you're not from Ashoka University, the first two sections and the name of the repo are irrelevant to you.

The Problem

The Ashoka University UG Facebook group had some uninvited guests that could jeopardize the safety of the group. Moreover, annually verifying whether a person is from Ashoka university by cross-checking every request to the group with the LMS directory is cumbersome & unreliable. A system is required to verify that the person requesting to join the FB group is really an Ashokan.

The solution

One possible solution is to ask some open-ended questions. If the answers are v liberal, then one can assume that the person applying is an Ashokan. However, some right wing fellows can also fake liberal answers and get into the group, in order to peek into the evil soup these liberal Ashokans are cooking up.

How can someone joining prove they're an Ashokan? By proving they have something only Ashokans can have. All UG Ashokans have an @ashoka.edu.in email address. One can prove they're an Ashokan if they can prove they have access to this email account. Hence, if they prove that they can send an email from this account, they can prove that they're Ashokans.

Then, let's go one step further and automate the entire process, from sending an email to the accepting/rejecting of FB join requests.

The Architecture

Let Bob be a moderator of the FB group & somebody with an email account (Bob is the automated system).

  1. Alice wants to join the Facebook group.
  2. Alice emails Bob with her Ashoka ID -- showing that she has access to an Ashoka ID & consequently, must be an Ashokan -- and asks for a unique code.
  3. Bob verifies the email, checks that the email is indeed from Ashoka University & is an undergraduate email address.
  4. Bob then encrypts Alice's email address with his secret key and emails this encrypted text. Let's call this encrypted text S. (Done using AES-256 in CBC mode using a random IV every time)
  5. Alice copies and pastes S into the Facebook form that asks for this encrypted text, and submits it.
  6. Bob reviews Alice's request, he decrypts her response (S) and finds the decrypted text to be a valid Ashoka email address.
  7. Bob makes a record of the fact that Alice's email address has been used, and accepts her request.

Now, let Mallory be some malicious person.

  1. Mallory wants to join the Facebook group but does not have access to the right email account.
  2. Scenario 1:
    • Through some means, she obtains Alice's code S and submits S on the Facebook form.
    • Bob reviews the request and finds it to be a valid email address.
    • However, as Bob made a record of this email being used when Alice joined the group, he finds this request to be a duplicate & rejects it.
  3. Scenario 2:
    • Mallory enters some jibberish that decrypts successfully.
    • Bob reviews the request and finds it to be an invalid email address and hence, rejects it.
  4. Scenario 3:
    • Alice gives her code to Mallory to join the group with.
    • Bob decrypts her response and finds the decrypted text to be a valid Ashoka email address.
    • He then accepts the request.
    • Mallory can join the group with Alice's help. Don't be like Alice.

Diving into the code

The code is documented & commented, you should not have too much of an issue understanding what's being done. Moreover, the code is divided into two independent sections:

  1. Email Verification: sub-module to fetch, verify & respond to emails. It also generates & validates the codes sent out. See verification.py and gmail_utils.py
  2. FB Automation: sub-module to run Selenium & login to Facebook, open the groups page, extract pending requests & respond to them based on a validation function. See fb_automation.py

Finally, these two sections are combined and run in main.py.

Python prerequisites

  1. pip3 install selenium
  2. pip3 install chromedriver
  3. pip3 install pycrypto
  4. pip3 install --upgrade google-api-python-client google-auth-httplib2 google-auth-oauthlib

config.json

You must have a JSON file that contains all info about the FB credentials, Google client secret, which emails to respond to, regex to validate an email etc. It should be structured as follows:

{"fb": {"email": "",// fb email to log in with "password": "",// fb password to log in with "group_url": "https://www.facebook.com/groups/SomeGroupHere/requests/"// the url of the group},"valid_email_regex": "^[a-z0-9]{1,20}\\.[a-z0-9]{1,20}_(ug|asp)[0-9]{2}@ashoka.edu.in$",// regex to validate an email address"email_subject": "Join FB Group",// the subject of the email one must enter"datafile": "./data/emails_joined.csv",// data file to store all email addresses that have successfully joined the group"client_secret": "./data/client_secret.json",// google client secret"access_token": "./data/access_token.pickle",// google access token"encryption_key": "superSecureEncryptionKey"// encryption key to encrypt/decrypt email addresses}

Running

Once you setup your config file & have your Google client secret ready, start the program using: python3 main.py 'path/to/config.json'

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - ashokatechmin/SpikedVodka: Automated Facebook Group Request Handling · GitHub
Skip to content

Repository files navigation

SpikedVodka - Automate FB Group Request Handling

If you're not from Ashoka University, the first two sections and the name of the repo are irrelevant to you.

The Problem

The Ashoka University UG Facebook group had some uninvited guests that could jeopardize the safety of the group. Moreover, annually verifying whether a person is from Ashoka university by cross-checking every request to the group with the LMS directory is cumbersome & unreliable. A system is required to verify that the person requesting to join the FB group is really an Ashokan.

The solution

One possible solution is to ask some open-ended questions. If the answers are v liberal, then one can assume that the person applying is an Ashokan. However, some right wing fellows can also fake liberal answers and get into the group, in order to peek into the evil soup these liberal Ashokans are cooking up.

How can someone joining prove they're an Ashokan? By proving they have something only Ashokans can have. All UG Ashokans have an @ashoka.edu.in email address. One can prove they're an Ashokan if they can prove they have access to this email account. Hence, if they prove that they can send an email from this account, they can prove that they're Ashokans.

Then, let's go one step further and automate the entire process, from sending an email to the accepting/rejecting of FB join requests.

The Architecture

Let Bob be a moderator of the FB group & somebody with an email account (Bob is the automated system).

  1. Alice wants to join the Facebook group.
  2. Alice emails Bob with her Ashoka ID -- showing that she has access to an Ashoka ID & consequently, must be an Ashokan -- and asks for a unique code.
  3. Bob verifies the email, checks that the email is indeed from Ashoka University & is an undergraduate email address.
  4. Bob then encrypts Alice's email address with his secret key and emails this encrypted text. Let's call this encrypted text S. (Done using AES-256 in CBC mode using a random IV every time)
  5. Alice copies and pastes S into the Facebook form that asks for this encrypted text, and submits it.
  6. Bob reviews Alice's request, he decrypts her response (S) and finds the decrypted text to be a valid Ashoka email address.
  7. Bob makes a record of the fact that Alice's email address has been used, and accepts her request.

Now, let Mallory be some malicious person.

  1. Mallory wants to join the Facebook group but does not have access to the right email account.
  2. Scenario 1:
    • Through some means, she obtains Alice's code S and submits S on the Facebook form.
    • Bob reviews the request and finds it to be a valid email address.
    • However, as Bob made a record of this email being used when Alice joined the group, he finds this request to be a duplicate & rejects it.
  3. Scenario 2:
    • Mallory enters some jibberish that decrypts successfully.
    • Bob reviews the request and finds it to be an invalid email address and hence, rejects it.
  4. Scenario 3:
    • Alice gives her code to Mallory to join the group with.
    • Bob decrypts her response and finds the decrypted text to be a valid Ashoka email address.
    • He then accepts the request.
    • Mallory can join the group with Alice's help. Don't be like Alice.

Diving into the code

The code is documented & commented, you should not have too much of an issue understanding what's being done. Moreover, the code is divided into two independent sections:

  1. Email Verification: sub-module to fetch, verify & respond to emails. It also generates & validates the codes sent out. See verification.py and gmail_utils.py
  2. FB Automation: sub-module to run Selenium & login to Facebook, open the groups page, extract pending requests & respond to them based on a validation function. See fb_automation.py

Finally, these two sections are combined and run in main.py.

Python prerequisites

  1. pip3 install selenium
  2. pip3 install chromedriver
  3. pip3 install pycrypto
  4. pip3 install --upgrade google-api-python-client google-auth-httplib2 google-auth-oauthlib

config.json

You must have a JSON file that contains all info about the FB credentials, Google client secret, which emails to respond to, regex to validate an email etc. It should be structured as follows:

{"fb": {"email": "",// fb email to log in with "password": "",// fb password to log in with "group_url": "https://www.facebook.com/groups/SomeGroupHere/requests/"// the url of the group},"valid_email_regex": "^[a-z0-9]{1,20}\\.[a-z0-9]{1,20}_(ug|asp)[0-9]{2}@ashoka.edu.in$",// regex to validate an email address"email_subject": "Join FB Group",// the subject of the email one must enter"datafile": "./data/emails_joined.csv",// data file to store all email addresses that have successfully joined the group"client_secret": "./data/client_secret.json",// google client secret"access_token": "./data/access_token.pickle",// google access token"encryption_key": "superSecureEncryptionKey"// encryption key to encrypt/decrypt email addresses}

Running

Once you setup your config file & have your Google client secret ready, start the program using: python3 main.py 'path/to/config.json'

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - ashokatechmin/SpikedVodka: Automated Facebook Group Request Handling · GitHub
Skip to content

Repository files navigation

SpikedVodka - Automate FB Group Request Handling

If you're not from Ashoka University, the first two sections and the name of the repo are irrelevant to you.

The Problem

The Ashoka University UG Facebook group had some uninvited guests that could jeopardize the safety of the group. Moreover, annually verifying whether a person is from Ashoka university by cross-checking every request to the group with the LMS directory is cumbersome & unreliable. A system is required to verify that the person requesting to join the FB group is really an Ashokan.

The solution

One possible solution is to ask some open-ended questions. If the answers are v liberal, then one can assume that the person applying is an Ashokan. However, some right wing fellows can also fake liberal answers and get into the group, in order to peek into the evil soup these liberal Ashokans are cooking up.

How can someone joining prove they're an Ashokan? By proving they have something only Ashokans can have. All UG Ashokans have an @ashoka.edu.in email address. One can prove they're an Ashokan if they can prove they have access to this email account. Hence, if they prove that they can send an email from this account, they can prove that they're Ashokans.

Then, let's go one step further and automate the entire process, from sending an email to the accepting/rejecting of FB join requests.

The Architecture

Let Bob be a moderator of the FB group & somebody with an email account (Bob is the automated system).

  1. Alice wants to join the Facebook group.
  2. Alice emails Bob with her Ashoka ID -- showing that she has access to an Ashoka ID & consequently, must be an Ashokan -- and asks for a unique code.
  3. Bob verifies the email, checks that the email is indeed from Ashoka University & is an undergraduate email address.
  4. Bob then encrypts Alice's email address with his secret key and emails this encrypted text. Let's call this encrypted text S. (Done using AES-256 in CBC mode using a random IV every time)
  5. Alice copies and pastes S into the Facebook form that asks for this encrypted text, and submits it.
  6. Bob reviews Alice's request, he decrypts her response (S) and finds the decrypted text to be a valid Ashoka email address.
  7. Bob makes a record of the fact that Alice's email address has been used, and accepts her request.

Now, let Mallory be some malicious person.

  1. Mallory wants to join the Facebook group but does not have access to the right email account.
  2. Scenario 1:
    • Through some means, she obtains Alice's code S and submits S on the Facebook form.
    • Bob reviews the request and finds it to be a valid email address.
    • However, as Bob made a record of this email being used when Alice joined the group, he finds this request to be a duplicate & rejects it.
  3. Scenario 2:
    • Mallory enters some jibberish that decrypts successfully.
    • Bob reviews the request and finds it to be an invalid email address and hence, rejects it.
  4. Scenario 3:
    • Alice gives her code to Mallory to join the group with.
    • Bob decrypts her response and finds the decrypted text to be a valid Ashoka email address.
    • He then accepts the request.
    • Mallory can join the group with Alice's help. Don't be like Alice.

Diving into the code

The code is documented & commented, you should not have too much of an issue understanding what's being done. Moreover, the code is divided into two independent sections:

  1. Email Verification: sub-module to fetch, verify & respond to emails. It also generates & validates the codes sent out. See verification.py and gmail_utils.py
  2. FB Automation: sub-module to run Selenium & login to Facebook, open the groups page, extract pending requests & respond to them based on a validation function. See fb_automation.py

Finally, these two sections are combined and run in main.py.

Python prerequisites

  1. pip3 install selenium
  2. pip3 install chromedriver
  3. pip3 install pycrypto
  4. pip3 install --upgrade google-api-python-client google-auth-httplib2 google-auth-oauthlib

config.json

You must have a JSON file that contains all info about the FB credentials, Google client secret, which emails to respond to, regex to validate an email etc. It should be structured as follows:

{"fb": {"email": "",// fb email to log in with "password": "",// fb password to log in with "group_url": "https://www.facebook.com/groups/SomeGroupHere/requests/"// the url of the group},"valid_email_regex": "^[a-z0-9]{1,20}\\.[a-z0-9]{1,20}_(ug|asp)[0-9]{2}@ashoka.edu.in$",// regex to validate an email address"email_subject": "Join FB Group",// the subject of the email one must enter"datafile": "./data/emails_joined.csv",// data file to store all email addresses that have successfully joined the group"client_secret": "./data/client_secret.json",// google client secret"access_token": "./data/access_token.pickle",// google access token"encryption_key": "superSecureEncryptionKey"// encryption key to encrypt/decrypt email addresses}

Running

Once you setup your config file & have your Google client secret ready, start the program using: python3 main.py 'path/to/config.json'

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - ashokatechmin/SpikedVodka: Automated Facebook Group Request Handling · GitHub
Skip to content

Repository files navigation

SpikedVodka - Automate FB Group Request Handling

If you're not from Ashoka University, the first two sections and the name of the repo are irrelevant to you.

The Problem

The Ashoka University UG Facebook group had some uninvited guests that could jeopardize the safety of the group. Moreover, annually verifying whether a person is from Ashoka university by cross-checking every request to the group with the LMS directory is cumbersome & unreliable. A system is required to verify that the person requesting to join the FB group is really an Ashokan.

The solution

One possible solution is to ask some open-ended questions. If the answers are v liberal, then one can assume that the person applying is an Ashokan. However, some right wing fellows can also fake liberal answers and get into the group, in order to peek into the evil soup these liberal Ashokans are cooking up.

How can someone joining prove they're an Ashokan? By proving they have something only Ashokans can have. All UG Ashokans have an @ashoka.edu.in email address. One can prove they're an Ashokan if they can prove they have access to this email account. Hence, if they prove that they can send an email from this account, they can prove that they're Ashokans.

Then, let's go one step further and automate the entire process, from sending an email to the accepting/rejecting of FB join requests.

The Architecture

Let Bob be a moderator of the FB group & somebody with an email account (Bob is the automated system).

  1. Alice wants to join the Facebook group.
  2. Alice emails Bob with her Ashoka ID -- showing that she has access to an Ashoka ID & consequently, must be an Ashokan -- and asks for a unique code.
  3. Bob verifies the email, checks that the email is indeed from Ashoka University & is an undergraduate email address.
  4. Bob then encrypts Alice's email address with his secret key and emails this encrypted text. Let's call this encrypted text S. (Done using AES-256 in CBC mode using a random IV every time)
  5. Alice copies and pastes S into the Facebook form that asks for this encrypted text, and submits it.
  6. Bob reviews Alice's request, he decrypts her response (S) and finds the decrypted text to be a valid Ashoka email address.
  7. Bob makes a record of the fact that Alice's email address has been used, and accepts her request.

Now, let Mallory be some malicious person.

  1. Mallory wants to join the Facebook group but does not have access to the right email account.
  2. Scenario 1:
    • Through some means, she obtains Alice's code S and submits S on the Facebook form.
    • Bob reviews the request and finds it to be a valid email address.
    • However, as Bob made a record of this email being used when Alice joined the group, he finds this request to be a duplicate & rejects it.
  3. Scenario 2:
    • Mallory enters some jibberish that decrypts successfully.
    • Bob reviews the request and finds it to be an invalid email address and hence, rejects it.
  4. Scenario 3:
    • Alice gives her code to Mallory to join the group with.
    • Bob decrypts her response and finds the decrypted text to be a valid Ashoka email address.
    • He then accepts the request.
    • Mallory can join the group with Alice's help. Don't be like Alice.

Diving into the code

The code is documented & commented, you should not have too much of an issue understanding what's being done. Moreover, the code is divided into two independent sections:

  1. Email Verification: sub-module to fetch, verify & respond to emails. It also generates & validates the codes sent out. See verification.py and gmail_utils.py
  2. FB Automation: sub-module to run Selenium & login to Facebook, open the groups page, extract pending requests & respond to them based on a validation function. See fb_automation.py

Finally, these two sections are combined and run in main.py.

Python prerequisites

  1. pip3 install selenium
  2. pip3 install chromedriver
  3. pip3 install pycrypto
  4. pip3 install --upgrade google-api-python-client google-auth-httplib2 google-auth-oauthlib

config.json

You must have a JSON file that contains all info about the FB credentials, Google client secret, which emails to respond to, regex to validate an email etc. It should be structured as follows:

{"fb": {"email": "",// fb email to log in with "password": "",// fb password to log in with "group_url": "https://www.facebook.com/groups/SomeGroupHere/requests/"// the url of the group},"valid_email_regex": "^[a-z0-9]{1,20}\\.[a-z0-9]{1,20}_(ug|asp)[0-9]{2}@ashoka.edu.in$",// regex to validate an email address"email_subject": "Join FB Group",// the subject of the email one must enter"datafile": "./data/emails_joined.csv",// data file to store all email addresses that have successfully joined the group"client_secret": "./data/client_secret.json",// google client secret"access_token": "./data/access_token.pickle",// google access token"encryption_key": "superSecureEncryptionKey"// encryption key to encrypt/decrypt email addresses}

Running

Once you setup your config file & have your Google client secret ready, start the program using: python3 main.py 'path/to/config.json'

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - ashokatechmin/SpikedVodka: Automated Facebook Group Request Handling · GitHub
Skip to content

Repository files navigation

SpikedVodka - Automate FB Group Request Handling

If you're not from Ashoka University, the first two sections and the name of the repo are irrelevant to you.

The Problem

The Ashoka University UG Facebook group had some uninvited guests that could jeopardize the safety of the group. Moreover, annually verifying whether a person is from Ashoka university by cross-checking every request to the group with the LMS directory is cumbersome & unreliable. A system is required to verify that the person requesting to join the FB group is really an Ashokan.

The solution

One possible solution is to ask some open-ended questions. If the answers are v liberal, then one can assume that the person applying is an Ashokan. However, some right wing fellows can also fake liberal answers and get into the group, in order to peek into the evil soup these liberal Ashokans are cooking up.

How can someone joining prove they're an Ashokan? By proving they have something only Ashokans can have. All UG Ashokans have an @ashoka.edu.in email address. One can prove they're an Ashokan if they can prove they have access to this email account. Hence, if they prove that they can send an email from this account, they can prove that they're Ashokans.

Then, let's go one step further and automate the entire process, from sending an email to the accepting/rejecting of FB join requests.

The Architecture

Let Bob be a moderator of the FB group & somebody with an email account (Bob is the automated system).

  1. Alice wants to join the Facebook group.
  2. Alice emails Bob with her Ashoka ID -- showing that she has access to an Ashoka ID & consequently, must be an Ashokan -- and asks for a unique code.
  3. Bob verifies the email, checks that the email is indeed from Ashoka University & is an undergraduate email address.
  4. Bob then encrypts Alice's email address with his secret key and emails this encrypted text. Let's call this encrypted text S. (Done using AES-256 in CBC mode using a random IV every time)
  5. Alice copies and pastes S into the Facebook form that asks for this encrypted text, and submits it.
  6. Bob reviews Alice's request, he decrypts her response (S) and finds the decrypted text to be a valid Ashoka email address.
  7. Bob makes a record of the fact that Alice's email address has been used, and accepts her request.

Now, let Mallory be some malicious person.

  1. Mallory wants to join the Facebook group but does not have access to the right email account.
  2. Scenario 1:
    • Through some means, she obtains Alice's code S and submits S on the Facebook form.
    • Bob reviews the request and finds it to be a valid email address.
    • However, as Bob made a record of this email being used when Alice joined the group, he finds this request to be a duplicate & rejects it.
  3. Scenario 2:
    • Mallory enters some jibberish that decrypts successfully.
    • Bob reviews the request and finds it to be an invalid email address and hence, rejects it.
  4. Scenario 3:
    • Alice gives her code to Mallory to join the group with.
    • Bob decrypts her response and finds the decrypted text to be a valid Ashoka email address.
    • He then accepts the request.
    • Mallory can join the group with Alice's help. Don't be like Alice.

Diving into the code

The code is documented & commented, you should not have too much of an issue understanding what's being done. Moreover, the code is divided into two independent sections:

  1. Email Verification: sub-module to fetch, verify & respond to emails. It also generates & validates the codes sent out. See verification.py and gmail_utils.py
  2. FB Automation: sub-module to run Selenium & login to Facebook, open the groups page, extract pending requests & respond to them based on a validation function. See fb_automation.py

Finally, these two sections are combined and run in main.py.

Python prerequisites

  1. pip3 install selenium
  2. pip3 install chromedriver
  3. pip3 install pycrypto
  4. pip3 install --upgrade google-api-python-client google-auth-httplib2 google-auth-oauthlib

config.json

You must have a JSON file that contains all info about the FB credentials, Google client secret, which emails to respond to, regex to validate an email etc. It should be structured as follows:

{"fb": {"email": "",// fb email to log in with "password": "",// fb password to log in with "group_url": "https://www.facebook.com/groups/SomeGroupHere/requests/"// the url of the group},"valid_email_regex": "^[a-z0-9]{1,20}\\.[a-z0-9]{1,20}_(ug|asp)[0-9]{2}@ashoka.edu.in$",// regex to validate an email address"email_subject": "Join FB Group",// the subject of the email one must enter"datafile": "./data/emails_joined.csv",// data file to store all email addresses that have successfully joined the group"client_secret": "./data/client_secret.json",// google client secret"access_token": "./data/access_token.pickle",// google access token"encryption_key": "superSecureEncryptionKey"// encryption key to encrypt/decrypt email addresses}

Running

Once you setup your config file & have your Google client secret ready, start the program using: python3 main.py 'path/to/config.json'

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - ashokatechmin/SpikedVodka: Automated Facebook Group Request Handling · GitHub
Skip to content

Repository files navigation

SpikedVodka - Automate FB Group Request Handling

If you're not from Ashoka University, the first two sections and the name of the repo are irrelevant to you.

The Problem

The Ashoka University UG Facebook group had some uninvited guests that could jeopardize the safety of the group. Moreover, annually verifying whether a person is from Ashoka university by cross-checking every request to the group with the LMS directory is cumbersome & unreliable. A system is required to verify that the person requesting to join the FB group is really an Ashokan.

The solution

One possible solution is to ask some open-ended questions. If the answers are v liberal, then one can assume that the person applying is an Ashokan. However, some right wing fellows can also fake liberal answers and get into the group, in order to peek into the evil soup these liberal Ashokans are cooking up.

How can someone joining prove they're an Ashokan? By proving they have something only Ashokans can have. All UG Ashokans have an @ashoka.edu.in email address. One can prove they're an Ashokan if they can prove they have access to this email account. Hence, if they prove that they can send an email from this account, they can prove that they're Ashokans.

Then, let's go one step further and automate the entire process, from sending an email to the accepting/rejecting of FB join requests.

The Architecture

Let Bob be a moderator of the FB group & somebody with an email account (Bob is the automated system).

  1. Alice wants to join the Facebook group.
  2. Alice emails Bob with her Ashoka ID -- showing that she has access to an Ashoka ID & consequently, must be an Ashokan -- and asks for a unique code.
  3. Bob verifies the email, checks that the email is indeed from Ashoka University & is an undergraduate email address.
  4. Bob then encrypts Alice's email address with his secret key and emails this encrypted text. Let's call this encrypted text S. (Done using AES-256 in CBC mode using a random IV every time)
  5. Alice copies and pastes S into the Facebook form that asks for this encrypted text, and submits it.
  6. Bob reviews Alice's request, he decrypts her response (S) and finds the decrypted text to be a valid Ashoka email address.
  7. Bob makes a record of the fact that Alice's email address has been used, and accepts her request.

Now, let Mallory be some malicious person.

  1. Mallory wants to join the Facebook group but does not have access to the right email account.
  2. Scenario 1:
    • Through some means, she obtains Alice's code S and submits S on the Facebook form.
    • Bob reviews the request and finds it to be a valid email address.
    • However, as Bob made a record of this email being used when Alice joined the group, he finds this request to be a duplicate & rejects it.
  3. Scenario 2:
    • Mallory enters some jibberish that decrypts successfully.
    • Bob reviews the request and finds it to be an invalid email address and hence, rejects it.
  4. Scenario 3:
    • Alice gives her code to Mallory to join the group with.
    • Bob decrypts her response and finds the decrypted text to be a valid Ashoka email address.
    • He then accepts the request.
    • Mallory can join the group with Alice's help. Don't be like Alice.

Diving into the code

The code is documented & commented, you should not have too much of an issue understanding what's being done. Moreover, the code is divided into two independent sections:

  1. Email Verification: sub-module to fetch, verify & respond to emails. It also generates & validates the codes sent out. See verification.py and gmail_utils.py
  2. FB Automation: sub-module to run Selenium & login to Facebook, open the groups page, extract pending requests & respond to them based on a validation function. See fb_automation.py

Finally, these two sections are combined and run in main.py.

Python prerequisites

  1. pip3 install selenium
  2. pip3 install chromedriver
  3. pip3 install pycrypto
  4. pip3 install --upgrade google-api-python-client google-auth-httplib2 google-auth-oauthlib

config.json

You must have a JSON file that contains all info about the FB credentials, Google client secret, which emails to respond to, regex to validate an email etc. It should be structured as follows:

{"fb": {"email": "",// fb email to log in with "password": "",// fb password to log in with "group_url": "https://www.facebook.com/groups/SomeGroupHere/requests/"// the url of the group},"valid_email_regex": "^[a-z0-9]{1,20}\\.[a-z0-9]{1,20}_(ug|asp)[0-9]{2}@ashoka.edu.in$",// regex to validate an email address"email_subject": "Join FB Group",// the subject of the email one must enter"datafile": "./data/emails_joined.csv",// data file to store all email addresses that have successfully joined the group"client_secret": "./data/client_secret.json",// google client secret"access_token": "./data/access_token.pickle",// google access token"encryption_key": "superSecureEncryptionKey"// encryption key to encrypt/decrypt email addresses}

Running

Once you setup your config file & have your Google client secret ready, start the program using: python3 main.py 'path/to/config.json'

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - ashokatechmin/SpikedVodka: Automated Facebook Group Request Handling · GitHub
Skip to content

Repository files navigation

SpikedVodka - Automate FB Group Request Handling

If you're not from Ashoka University, the first two sections and the name of the repo are irrelevant to you.

The Problem

The Ashoka University UG Facebook group had some uninvited guests that could jeopardize the safety of the group. Moreover, annually verifying whether a person is from Ashoka university by cross-checking every request to the group with the LMS directory is cumbersome & unreliable. A system is required to verify that the person requesting to join the FB group is really an Ashokan.

The solution

One possible solution is to ask some open-ended questions. If the answers are v liberal, then one can assume that the person applying is an Ashokan. However, some right wing fellows can also fake liberal answers and get into the group, in order to peek into the evil soup these liberal Ashokans are cooking up.

How can someone joining prove they're an Ashokan? By proving they have something only Ashokans can have. All UG Ashokans have an @ashoka.edu.in email address. One can prove they're an Ashokan if they can prove they have access to this email account. Hence, if they prove that they can send an email from this account, they can prove that they're Ashokans.

Then, let's go one step further and automate the entire process, from sending an email to the accepting/rejecting of FB join requests.

The Architecture

Let Bob be a moderator of the FB group & somebody with an email account (Bob is the automated system).

  1. Alice wants to join the Facebook group.
  2. Alice emails Bob with her Ashoka ID -- showing that she has access to an Ashoka ID & consequently, must be an Ashokan -- and asks for a unique code.
  3. Bob verifies the email, checks that the email is indeed from Ashoka University & is an undergraduate email address.
  4. Bob then encrypts Alice's email address with his secret key and emails this encrypted text. Let's call this encrypted text S. (Done using AES-256 in CBC mode using a random IV every time)
  5. Alice copies and pastes S into the Facebook form that asks for this encrypted text, and submits it.
  6. Bob reviews Alice's request, he decrypts her response (S) and finds the decrypted text to be a valid Ashoka email address.
  7. Bob makes a record of the fact that Alice's email address has been used, and accepts her request.

Now, let Mallory be some malicious person.

  1. Mallory wants to join the Facebook group but does not have access to the right email account.
  2. Scenario 1:
    • Through some means, she obtains Alice's code S and submits S on the Facebook form.
    • Bob reviews the request and finds it to be a valid email address.
    • However, as Bob made a record of this email being used when Alice joined the group, he finds this request to be a duplicate & rejects it.
  3. Scenario 2:
    • Mallory enters some jibberish that decrypts successfully.
    • Bob reviews the request and finds it to be an invalid email address and hence, rejects it.
  4. Scenario 3:
    • Alice gives her code to Mallory to join the group with.
    • Bob decrypts her response and finds the decrypted text to be a valid Ashoka email address.
    • He then accepts the request.
    • Mallory can join the group with Alice's help. Don't be like Alice.

Diving into the code

The code is documented & commented, you should not have too much of an issue understanding what's being done. Moreover, the code is divided into two independent sections:

  1. Email Verification: sub-module to fetch, verify & respond to emails. It also generates & validates the codes sent out. See verification.py and gmail_utils.py
  2. FB Automation: sub-module to run Selenium & login to Facebook, open the groups page, extract pending requests & respond to them based on a validation function. See fb_automation.py

Finally, these two sections are combined and run in main.py.

Python prerequisites

  1. pip3 install selenium
  2. pip3 install chromedriver
  3. pip3 install pycrypto
  4. pip3 install --upgrade google-api-python-client google-auth-httplib2 google-auth-oauthlib

config.json

You must have a JSON file that contains all info about the FB credentials, Google client secret, which emails to respond to, regex to validate an email etc. It should be structured as follows:

{"fb": {"email": "",// fb email to log in with "password": "",// fb password to log in with "group_url": "https://www.facebook.com/groups/SomeGroupHere/requests/"// the url of the group},"valid_email_regex": "^[a-z0-9]{1,20}\\.[a-z0-9]{1,20}_(ug|asp)[0-9]{2}@ashoka.edu.in$",// regex to validate an email address"email_subject": "Join FB Group",// the subject of the email one must enter"datafile": "./data/emails_joined.csv",// data file to store all email addresses that have successfully joined the group"client_secret": "./data/client_secret.json",// google client secret"access_token": "./data/access_token.pickle",// google access token"encryption_key": "superSecureEncryptionKey"// encryption key to encrypt/decrypt email addresses}

Running

Once you setup your config file & have your Google client secret ready, start the program using: python3 main.py 'path/to/config.json'

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - ashokatechmin/SpikedVodka: Automated Facebook Group Request Handling · GitHub
Skip to content

Repository files navigation

SpikedVodka - Automate FB Group Request Handling

If you're not from Ashoka University, the first two sections and the name of the repo are irrelevant to you.

The Problem

The Ashoka University UG Facebook group had some uninvited guests that could jeopardize the safety of the group. Moreover, annually verifying whether a person is from Ashoka university by cross-checking every request to the group with the LMS directory is cumbersome & unreliable. A system is required to verify that the person requesting to join the FB group is really an Ashokan.

The solution

One possible solution is to ask some open-ended questions. If the answers are v liberal, then one can assume that the person applying is an Ashokan. However, some right wing fellows can also fake liberal answers and get into the group, in order to peek into the evil soup these liberal Ashokans are cooking up.

How can someone joining prove they're an Ashokan? By proving they have something only Ashokans can have. All UG Ashokans have an @ashoka.edu.in email address. One can prove they're an Ashokan if they can prove they have access to this email account. Hence, if they prove that they can send an email from this account, they can prove that they're Ashokans.

Then, let's go one step further and automate the entire process, from sending an email to the accepting/rejecting of FB join requests.

The Architecture

Let Bob be a moderator of the FB group & somebody with an email account (Bob is the automated system).

  1. Alice wants to join the Facebook group.
  2. Alice emails Bob with her Ashoka ID -- showing that she has access to an Ashoka ID & consequently, must be an Ashokan -- and asks for a unique code.
  3. Bob verifies the email, checks that the email is indeed from Ashoka University & is an undergraduate email address.
  4. Bob then encrypts Alice's email address with his secret key and emails this encrypted text. Let's call this encrypted text S. (Done using AES-256 in CBC mode using a random IV every time)
  5. Alice copies and pastes S into the Facebook form that asks for this encrypted text, and submits it.
  6. Bob reviews Alice's request, he decrypts her response (S) and finds the decrypted text to be a valid Ashoka email address.
  7. Bob makes a record of the fact that Alice's email address has been used, and accepts her request.

Now, let Mallory be some malicious person.

  1. Mallory wants to join the Facebook group but does not have access to the right email account.
  2. Scenario 1:
    • Through some means, she obtains Alice's code S and submits S on the Facebook form.
    • Bob reviews the request and finds it to be a valid email address.
    • However, as Bob made a record of this email being used when Alice joined the group, he finds this request to be a duplicate & rejects it.
  3. Scenario 2:
    • Mallory enters some jibberish that decrypts successfully.
    • Bob reviews the request and finds it to be an invalid email address and hence, rejects it.
  4. Scenario 3:
    • Alice gives her code to Mallory to join the group with.
    • Bob decrypts her response and finds the decrypted text to be a valid Ashoka email address.
    • He then accepts the request.
    • Mallory can join the group with Alice's help. Don't be like Alice.

Diving into the code

The code is documented & commented, you should not have too much of an issue understanding what's being done. Moreover, the code is divided into two independent sections:

  1. Email Verification: sub-module to fetch, verify & respond to emails. It also generates & validates the codes sent out. See verification.py and gmail_utils.py
  2. FB Automation: sub-module to run Selenium & login to Facebook, open the groups page, extract pending requests & respond to them based on a validation function. See fb_automation.py

Finally, these two sections are combined and run in main.py.

Python prerequisites

  1. pip3 install selenium
  2. pip3 install chromedriver
  3. pip3 install pycrypto
  4. pip3 install --upgrade google-api-python-client google-auth-httplib2 google-auth-oauthlib

config.json

You must have a JSON file that contains all info about the FB credentials, Google client secret, which emails to respond to, regex to validate an email etc. It should be structured as follows:

{"fb": {"email": "",// fb email to log in with "password": "",// fb password to log in with "group_url": "https://www.facebook.com/groups/SomeGroupHere/requests/"// the url of the group},"valid_email_regex": "^[a-z0-9]{1,20}\\.[a-z0-9]{1,20}_(ug|asp)[0-9]{2}@ashoka.edu.in$",// regex to validate an email address"email_subject": "Join FB Group",// the subject of the email one must enter"datafile": "./data/emails_joined.csv",// data file to store all email addresses that have successfully joined the group"client_secret": "./data/client_secret.json",// google client secret"access_token": "./data/access_token.pickle",// google access token"encryption_key": "superSecureEncryptionKey"// encryption key to encrypt/decrypt email addresses}

Running

Once you setup your config file & have your Google client secret ready, start the program using: python3 main.py 'path/to/config.json'

Releases

Packages

Used by

Contributors

Languages