Security Engineer Joey Tyson Discovers Facebook Security Hole

Security Engineer Joey Tyson has discovered a new security hole in Facebook that allows a seemingly innocent web page steal Facebook user's private data.

In a private demonstration sent to Facebook, Joey showed the two behaviors of Facebook platform can be combined to steal data silently.

From Joey's Blog: #-Link-Snipped-#

In my proof-of-concept demonstration, I loaded a harmless-looking web page on a server external to Facebook. The page included code for an inline frame sized to be invisible to the user. This frame then loaded the login page for a Facebook application. If the user has already authorized an application, its login page will automatically forward to the application, and that’s exactly what I wanted to happen. I chose FarmVille for my demo, since it has a wide install base. Keep in mind that while FarmVille currently lists about 83 million monthly active users, the attack would have worked for anyone who has authorized the application, regardless of how long ago. The attack could also target multiple applications at once using multiple iframes, meaning nearly any of Facebook’s 400 million active users could have fallen prey.

Replies

You are reading an archived discussion.

Related Posts

what is the use of clutch in automobiles.recently a bike has been launched without clutch.explain and do comment
can anyone tell me How this VoIP works? How we are able to call through IP address
People at 9to5 have found that iPhone's next version will support Video Chat - one of the most wanted features on iPhone. Take a look: Video Chat Moderators, Chat Room,...
Hi, I am interested in doing MS in Image processing.Would that be a good choice given my degree and work exp. ? I have done a BE in electronics and...
i am saranya , doing 1st year cse, how to present a paper, what are the things to be followed while presenting a paper, please suggest me, how to choose...