Login Register






Facebook vulnerability based on tokens filter_list
Author
Message
Facebook vulnerability based on tokens #1
Greetings, yet another Facebook vulnerability was discovered that may have big consequences. This vulnerability is based on leaking tokens of the users, thus being able to access private messages, credit card information, etc. This is a a chain of 3 vulnerabilities explained in the articles like:
Quote:
  1. Experts noticed that the “View As” allows displaying the profile as a read-only interface. but the platform fails to validate the content submitted through text box that allows people to wish happy birthday to their friends(this is the first bug). The experts discovered that it is possible to post a video through this field.
  2. The second issue is related to the fact that the video uploader generated an access token that had the permissions of the Facebook mobile app when posting a video in the text box.
  3. The third bug is that the token generated was not for the user who had been using “View As” but for the one whose profile was being viewed, this means that attackers could obtain the token from the page’s HTML code and use it to take over a targeted user’s account.

I find this vulnerability pretty interesting because it's acting like some kind of "worm".
For more information you can read the full article.
[Image: iQDVDdD.gif]

Reply

RE: Facebook vulnerability based on tokens #2
Coincidentally, I bookmarked this at work and was about to create a thread.

It's certainly significant, and the UK Is asking Mark Zuckerberg to face a series of questions. No doubt, he'll have quite a few sleepless nights.
[Image: AD83g1A.png]

Reply

RE: Facebook vulnerability based on tokens #3
I realy hope there will be some talks like it was back with the Cambridge analitica. aaand I wish I knew about the issue back in 2017. I could have hacked soo many profiles Sad(

Reply

Facebook vulnerability based on tokens #4
I am still waiting to see if any of these organizations get fined in terms of GDPR...

It's so flawed standard that all these organizations will keep evading it...

Same with British Airways, got pwned a while ago and nothing in terms of their GDPR fine!

Note: GDPR doesn't only affect EU organizations, but also organizations that deal with EU providers/clients. Correct me if wrong though.

Reply

RE: Facebook vulnerability based on tokens #5
Thanks for the information. Another scandal for fb... and yet it doesn't prevent people from registering.

Reply

RE: Facebook vulnerability based on tokens #6
(10-02-2018, 12:29 PM)BitFaces Wrote: Note: GDPR doesn't only affect EU organizations, but also organizations that deal with EU providers/clients. Correct me if wrong though.

Correct.

As long as It's within the EU jurisdiction.
[Image: AD83g1A.png]

Reply

RE: Facebook vulnerability based on tokens #7
(11-07-2018, 07:20 PM)gurami Wrote: Facebook has recently turned out to be weak

It's sharing functionality Is very difficult to monitor and keep your data anonymized.

For example, If you've set your friend's list to private and you have multiple mutual friends with other users, they're exposed on their profile hence no longer private. Using a systematic approach (moving from one user-profile to another), most friends will be revealed- I've done It quite a few times.
[Image: AD83g1A.png]

Reply

RE: Facebook vulnerability based on tokens #8
Well.. Facebook is an evil actually.

Reply