On TechRepublic: Why Android beats iPhone
BNET Business Network:
BNET
TechRepublic
ZDNet

August 25th, 2008

Facebook refuses to fix obvious security flaw

Posted by Ryan Naraine @ 3:44 pm

Categories: Anti Virus, Arbitrary Code Execution, Browsers, Data theft, Exploit code, Facebook, Hackers, Malware, Patch Watch, Pen testing, Privacy, Social Networking Applications, Viruses and Worms, Vulnerability research, Web 2.0

Tags: Facebook, Register, Social Networking, Cyberthreats, Security, Viruses And Worms, Online Communications, Marketing, Advertising & Promotion, Ryan Naraine

Facebook refuses to fix obvious security flaw

[ UPDATE:  Facebook has reversed itself and fixed this vulnerability ] 

The Register’s Dan Goodin has the scoop on an obvious security vulnerability that’s being ignored by the powers at Facebook.

The issue, as demonstrated by this proof-of-concept, shows how a social network application can be rigged to hijack a Facebook user’s session identification cookies, deliver pop-up messages or change the color of Facebook pages.

“With a little extra work, an attacker could probably do much more, including send and read messages from a user’s account, change privacy settings and add or delete Facebook friends,” according to the report.

When I tested the code while logged in to Facebook, it worked as advertised and proves conclusively that Facebook fails to sanitize the content of third-party applications.  This exposes Facebook’s massive user base to a variety of hacker attacks.

[ SEE: Web worms squirm through Facebook, MySpace ]

Worse, the developer who reported the flaw to Facebook says the company has refused to acknowledge the risk.

  • Wachelka said he filed a bug report with Facebook on Friday and promptly received a message saying the matter had been closed. “Our FBML tags are written not to run Javascript,” Facebook asserted.

A weakness in Facebook’s filtering recently exposed users to a malicious worm attack via the site’s commenting system.

* Image source:  We Blog Cartoons.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 11 Talkback(s)
Indeed
Let's hope the former turns out to be true, not the latter. (Read the rest)
Posted by: d.s.williams Posted on: 09/25/08  (Edited: 09/26/08 @ 01:11) You are currently: a Guest | | Terms of Use
Fixed.  ZDNET_guest666 | 08/26/08
Yup  Ryan NaraineZDNet Moderator | 08/26/08
The problem with pro-active security  Michael Kelly | 08/26/08
Headline of this sort aren't good for business  voska1 | 08/26/08
RE: Facebook refuses to fix obvious security flaw  phatkat | 08/26/08
Probably because  zenotek | 08/26/08
Not much  d.s.williams | 08/28/08
RE: Facebook refuses to fix obvious security flaw  Bozzer | 08/26/08
Sharing Facebook articles on ZDNet  d.s.williams | 08/28/08
Security Risks vs ROI  Dr_Zinj | 09/08/08
Indeed  d.s.williams | 09/25/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here