When you say it is client-side, it happens outside the control of the server, so there is not much you can do about it. If you are asking why Facebook still does this, this is not really for security but to protect normal users that do not know javascript from running code (that they don't know how to read) into the console. This is common for sites that promise auto-liker service or other Facebook functionality bots after you do what they ask you to do, where in most cases, they give you a snip of javascript to run in console.
facebook auto like script nulled and void
Facebook combats scraping and has protection to detect automatic scrapers. To avoid being blocked, you need to use a proxy with cloud extraction services. Still, Facebook keeps improving its protection; so be careful with automatic scraping. 2ff7e9595c
Comments