Adding &width=px&height=px allows for more specific dimensions.
There is no universal formula like facebook.com/viewhiddenpic/[username] . If you do not have the exact hash (the random string of letters and numbers in the URL) generated by Facebook’s servers, the link is dead. You cannot guess it, and no third-party website can generate it just by looking at a public profile link.