• Home
  • News
  • Artificial Intelligence
  • Internet of Things
  • Open Source
  • Hardware
  • Software
  • Security
  • Whitepapers
  • Industry Voice
  • Data Strategy Spotlight
  • Newsletters
  • Whitepapers
    • Inqlogo 120x194
      Five things you should look for in choosing a Testing provider

      Choosing a Testing Partner can be complex.  So what do you look for?  This guide offers insight into the qualities you must look for in choosing a Testing provider.  Download now to learn more.

      Download
      Inqlogo 120x194
      Your questions answered: How to protect your data in the cloud

      The number of successful cyberattacks per year per company has increased by 46% over the last four years. But what really needs to be considered when exploring a solution? What questions need to be asked? Download to find out...

      Download
      Find whitepapers
      Search by title or subject area
      View all whitepapers
  • Follow us
    • Twitter
    • Newsletters
    • Facebook
  • Newsletter
  • Industry Voice
  • Data Strategy Spotlight
The Inquirer
The Inquirer
  • Home
  • News
  • Artificial Intelligence
  • Internet of Things
  • Open Source
  • Hardware
  • Software
  • Security
  • Trending
  • General election
  • Huawei sues FCC
  • Xerox vs HP
  • Galaxy S11
  • McAfee 2020
The Inquirer
  • Software

Facebook security flaw remotely controls accounts

No friend request required

  • Lawrence Latif
  • Lawrence Latif
  • @illiteratehack
  • 07 July 2010
  • Tweet  
  • Facebook  
  •  
  •  
  • Send to  
0 Comments

SECURITY RESEARCHERS have found a glaring security fault with Facebook that allows the "remote control" of accounts.

Roger Thompson chief research officer at AVG revealed a Javascript injection attack that lures users by providing a link to a video, which it claims "99% of people can't watch". The link forwards users to another page that asks them to paste Javascript code into their browser's address bar.

Upon entering the code users are taken to another page that states that the user "likes" the video and adds a link to it in the user's Facebook status. Thompson says that it is the first such case his team are aware of in which Facebook accounts are remotely controlled.

The question is why does Facebook's supposedly secure and privacy aware site allow a relatively simple bit of Javascript code to alter a user's status and even take actions on behalf of the user?

According to Thompson, his team is unaware of what the payload of the attack is, meaning its true nature may not be as benign as first appearances. Nevertheless, Thompson states that the hack is already successful with over 600,000 users "liking" the video.

As for Facebook, this sort of disregard for security or privacy is merely par for the course. Until the firm sorts itself out, Thompson's advice is clear, do not enter code directly into the browser's address bar. µ

  • Tweet  
  • Facebook  
  •  
  •  
  • Send to  
  • Topics
  • Software

INQ Latest

Google is blocking some smaller Linux web browser from its services
Google is blocking some smaller Linux web browser from its services

Block to the future

  • Software
  • 16 December 2019
The Pirate Bay launches its own streaming service called 'BayStream'
The Pirate Bay launches its own streaming service called 'BayStream'

My bay or the highway

  • Controversy
  • 16 December 2019
Amazon Echo Studio review
Amazon Echo Studio review

Firm's first high-end speaker gets the thumbs up from us

  • Hardware
  • 16 December 2019
BBC is receiving increasing calls to change its funding model
Boris Johnson could decriminalise BBC licence fee dodging

Those who escape fines will be very Jammy Dodgers

  • Infrastructure
  • 16 December 2019
Back to Top

Most read

Apple's iPhone 12 won't see a significant price increase, claims Kuo
Apple's iPhone 12 won't see a significant price increase, claims analyst
Apple's parental controls in iOS 13.3 can be easily bypassed
Apple's parental controls in iOS 13.3 can be easily bypassed
Comet Lake-S leaks keep hitting earth
Intel Comet Lake-S leak teases AMD-chasing six-core Core i5-10600
Windows 7 goes end-of-life in a month
Windows 7 goes end-of-life in a month
OnePlus 8 Lite leak hints at a return to the mid-range
OnePlus 8 Lite leak hints at a return to the mid-range
  • Contact
  • Marketing solutions
  • Enterprise IT Events
  • Incisive Media
  • Terms & conditions
  • Policies
  • Careers
  • Twitter
  • Newsletters
  • Facebook

© Incisive Business Media (IP) Limited, Published by Incisive Business Media Limited, New London House, 172 Drury Lane, London WC2B 5QR, registered in England and Wales with company registration numbers 09177174 & 09178013

Digital publisher of the year
Digital publisher of the year 2010, 2013, 2016 & 2017