![]() |
|
Facebook vulnerability based on tokens - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: General (https://sinister.li/Forum-General) +--- Forum: World News (https://sinister.li/Forum-World-News) +--- Thread: Facebook vulnerability based on tokens (/Thread-Facebook-vulnerability-based-on-tokens) |
Facebook vulnerability based on tokens - Cr3aTor - 10-02-2018 Greetings, yet another Facebook vulnerability was discovered that may have big consequences. This vulnerability is based on leaking tokens of the users, thus being able to access private messages, credit card information, etc. This is a a chain of 3 vulnerabilities explained in the articles like: Quote: I find this vulnerability pretty interesting because it's acting like some kind of "worm". For more information you can read the full article. RE: Facebook vulnerability based on tokens - mothered - 10-02-2018 Coincidentally, I bookmarked this at work and was about to create a thread. It's certainly significant, and the UK Is asking Mark Zuckerberg to face a series of questions. No doubt, he'll have quite a few sleepless nights. RE: Facebook vulnerability based on tokens - Sun0228 - 10-02-2018 I realy hope there will be some talks like it was back with the Cambridge analitica. aaand I wish I knew about the issue back in 2017. I could have hacked soo many profiles (
Facebook vulnerability based on tokens - BitFaces - 10-02-2018 I am still waiting to see if any of these organizations get fined in terms of GDPR... It's so flawed standard that all these organizations will keep evading it... Same with British Airways, got pwned a while ago and nothing in terms of their GDPR fine! Note: GDPR doesn't only affect EU organizations, but also organizations that deal with EU providers/clients. Correct me if wrong though. RE: Facebook vulnerability based on tokens - arduinomeat - 10-02-2018 Thanks for the information. Another scandal for fb... and yet it doesn't prevent people from registering. RE: Facebook vulnerability based on tokens - mothered - 10-03-2018 (10-02-2018, 12:29 PM)BitFaces Wrote: Note: GDPR doesn't only affect EU organizations, but also organizations that deal with EU providers/clients. Correct me if wrong though. Correct. As long as It's within the EU jurisdiction. RE: Facebook vulnerability based on tokens - mothered - 11-08-2018 (11-07-2018, 07:20 PM)gurami Wrote: Facebook has recently turned out to be weak It's sharing functionality Is very difficult to monitor and keep your data anonymized. For example, If you've set your friend's list to private and you have multiple mutual friends with other users, they're exposed on their profile hence no longer private. Using a systematic approach (moving from one user-profile to another), most friends will be revealed- I've done It quite a few times. RE: Facebook vulnerability based on tokens - ThunderGod - 11-12-2018 Well.. Facebook is an evil actually. |