Thursday, August 6, 2009

Facebook personal info leak vulnerability
- or -
How your identity can be compromised just by reading forum posts.



Update: The issue has now been resolved. I've written a full disclosure, but you should read this post first in order to follow it.

I've stumbled across a small security vulnerability in Facebook that, after some thought, turned out to be a way to launch a powerful and surprising attack.
The attack allows personal information including full name, profile picture, and friends list to leak to an eagerly awaiting hacker. The uniqueness of this attack, is that the unaware user's data may be stolen when she is surfing a legitimate, trusted site, not a site controlled by the attacker.

As a video is worth a thousand words, I've made one to show the proposed hack.
The video contains no artificial ingredients behind the scenes. It is completely “live” and was edited only for brevity.





What did I just see?
By merely viewing a forum page containing the rouge image, a user's personal information (full name, profile picture, and friends list) can be obtained by a hacker. It is not the image itself that does the trick. Instead, when the browser fetches the image, a chain-reaction starts that delivers these details to the hacker. The chain reaction ends with a valid image, which means that the unknowing user would not have a clue that anything out of the ordinary just happened.
In addition, note that a user's details are also at risk when one of his friends falls victim to this attack.

What can this be used for?
First off, it means your surfing anonymity is breached.
Any site you visit might contain the attacking image, and your identity is subsequently uncovered. Obviously, a malicious site owner may place the image in his site with the intention of launching the attack, but, as shown this is not the only case. In many sites such as forums and blogs, any passing user may be able to post the attacking image, via a comment for example, and steal the user's data as demonstrated in the video.
Imagine that someone could link your name and picture to all the web sites you visit, forums you read, and blogs you follow...
Furthermore, combined with another vulnerability that discovers your email address (any XSS will do) and you get spammer's paradise: A self-creating mailing list of people that are interested in any specific topic, by attacking relevant forums or web sites.

How does it work?
This hack only works if the user is logged on to Facebook during the attack. However, it is very common for users to have their Facebook page permanently open while doing other things. This, together with the vast amount of Facebook users, makes this attack a serious threat.
In the professional jargon, it falls under the category of CSRF attacks, which are very interesting and somewhat unintuitive. In a CSRF attack Evil Joe manages to trick your computer into performing actions on your behalf, without your knowledge or consent. Unlike classic attacks in which the hacker “breaks into” some computer to do his deed. While the potential damage of CSRF attacks is very severe, they are not generally well known by both users and web developers. Creating web sites that are not susceptible to them is tricky and requires special attention.
I've notified the Facebook security team about this issue, and it should hopefully be resolved soon.

Summary
From a technical point of view, I think this exploit is elegant and surprisingly powerful. So, I'll be sharing the details in a full disclosure, as soon as the threat is removed. If you're interested, check back soon, or follow.
In the meantime, I think that the mere existence of this attack should be an eye-opener to the surprising dangers lurking on the Web. It definitely was for me.

68 comments:

  1. Not being especially technical, I'm left wondering... if I open, rather than a new tab, another instance of the same browser... or a different browser while logged in... does that address the threat?

    BTW, thanks a lot for this!

    ReplyDelete
  2. Rich L, it very much depends on your choice of browser (IE7 works, IE8/FF/GC not), and how you open the new instance (ctrl+n not, running the exe yes but only for IE7, "New Session" in IE8 and "private browsing" for all the browsers also yes)...

    But since you said you're not very technical, I'll just let you know that you're USUALLY logged in ALL THE TIME anyway, even if your browser is not open - do you have to enter your password everytime you go to Facebook...?

    ReplyDelete
  3. Facebook hacking is spreading all over. The hackers can hack your personal information so be careful when you are not using your facebook than make sure you are logout from your profile.

    ReplyDelete
  4. Avid, thanks for sharing knowledge on this topic. appreciated

    ReplyDelete
  5. Nice blog and I like that very much and want to share some thing about the site where you can found the much interesting thing about the facebook fans and twitters followers, If you are interested then visit the link.

    ReplyDelete
  6. Oh- I know alllll about this as I fell victim to it. Good post, but a little late for me.

    ReplyDelete
  7. nice sharing..this sharing will userfull for other safety while social

    ReplyDelete
  8. It seems these types of vulnerabilities are popping up more and more.

    ReplyDelete
  9. I like this blog so much. Respctive blog it is for the all world famous fashion models. Really here is an amazing sharing you have done. Thanks for sharing this post so much. Congratulation. Thanks...
    zak³ady bukmacherskie
    zak³ady sportowe
    Stop Sweating and Start Living
    bukmacherzy

    ReplyDelete
    Replies
    1. f you are paying attention, but this is my duty to inform you that virtual administrative

      Delete
  10. If you are paying attention, but this is my duty to inform you that virtual administrative helper a very devoted service and can be practical anywhere you want and get improved results.

    ReplyDelete
  11. Please keep them future. Greets! This is a in fact fine read for me, Must come clean that you are being being of the best blogger.

    ReplyDelete
  12. Not being especially technical, I'm left wondering... if I open, rather than a new tab, another instance of the same browser... or a different browser while logged in... does that address the threat?

    BTW, thanks a lot for this!
    buy traffic
    buy web traffic

    ReplyDelete
  13. Nice find with the exploit... glad it has been patched. Seems like there are so many security/privacy risk when you browse the web still logged in to facebook.

    ReplyDelete
  14. Please keep them future. Greets! This is a in fact fine read for me, Must come clean that you are being being of the best blogger.
    Mobil Apps

    ReplyDelete
  15. Well, it does a little confusing at this time. But maybe with this we can say it was a big chance to us to realize facebook is not a place to tell everything about our personal life.

    ReplyDelete
  16. People shouldn't put as much personal information on facebook.

    ReplyDelete
  17. Its really an informative post. Thanks for sharing your post..

    ReplyDelete
    Replies
    1. People shouldn't put as much personal information Surf Movies

      Delete
  18. As when i read your article, I found your blog quite informative. Thanks..

    ReplyDelete
  19. It definitely was for me. Yes, you are right.

    ReplyDelete
  20. This site is amazing awesome to me, I am being impressed by this great site.

    ReplyDelete
  21. Thanks a lot for sharing such a wonderful post, it is a very nice site i really enjoyed to visit this site.
    Trendy jewelry

    ReplyDelete
  22. Really fantastic article regarding the project. I just really love it. Thanks for making a wonderful share!

    ReplyDelete
  23. Very informative and impressive post you have written, this is quite interesting
    and i have went through it completely, an upgraded information is shared, keep
    sharing such valuable information.

    ReplyDelete
  24. Thanks a lot for sharing such a wonderful post, it is a very nice site i really
    enjoyed to visit this site.

    ReplyDelete
  25. Thanks a lot for sharing such a wonderful post, it is a very nice site i really
    enjoyed to visit this site.

    ReplyDelete
  26. AshishKamotra, Chief Executive Officer, Tally on cloud Adapt, Web enabling software in India by Software India Pvt. Ltd., India Soft-2012, HICC, Hyderabad, Andhra Pradesh. Running windows applications on IPad running windows applications on Android Adapt specializes in Microsoft SharePoint, Navision on cloud, Microsoft Dynamics CRM, Sage CRM, Microsoft .Net, MS SQL & Power Builder.
    http://www.youtube.com/watch?v=Wk8545AmoyI

    ReplyDelete
  27. GPS TRACKER,USED CARS,AUTO PARTS and CAR RENTALS
    Autos Ghana Limited buy all your new cars and used cars, heavy constructional equipment including auto parts  from USA whiles you pay in Ghana or worldwide under secured and legitimate processes. Track your vehicle with real time GPS tracker with Autos Ghana tracking services. Autos Ghana Limited also helps with all your auction car purchases including registrations and shipping.

    USED CARS
    Car parts
    GPS TRACKER
    Car rentals
    New cars

    ReplyDelete
  28. Running windows applications on Android, Running windows applications on I pad &
    SAP on cloud by Adapt Software India.
    AshishKamotra, Chief Executive Officer, Running windows applications on Android, Running windows applications on I pad by Software India Pvt. Ltd., India Soft-2012, HICC, Hyderabad, Andhra Pradesh. Adapt specializes in SAP on cloud Microsoft Dynamics CRM, Sage CRM, Microsoft .Net, MS SQL & Power Builder.

    SAP on cloud
    Running windows applications on iPad
    Running windows applications on Android

    ReplyDelete
  29. Running windows applications on Android, Running windows applications on I pad &
    SAP on cloud by Adapt Software India.
    AshishKamotra, Chief Executive Officer, Running windows applications on Android, Running windows applications on I pad by Software India Pvt. Ltd., India Soft-2012, HICC, Hyderabad, Andhra Pradesh. Adapt specializes in SAP on cloud Microsoft Dynamics CRM, Sage CRM, Microsoft .Net, MS SQL & Power Builder.

    SAP on cloud
    Running windows applications on iPad
    Running windows applications on Android
    Go-Global
    Remote access software

    ReplyDelete
  30. What is SharePoint, Microsoft Sharepoint 2013,and Microsoft Sharepoint 2010, Sharepoint Consulting.

    Best Case Studies of Document Management System implementations by Adapt India Software Private Limited,
    Document Management Solution on Microsoft SharePoint to automate your business processes and facilitate exchange of documents and information internallyand with your Sub Contractors with pre- defined workflows triggered with approvals, authorizations ,co-authorizations and authentications.

    Document Management Solution

    Sharepoint
    Sharepoint 2013
    Document Management
    Sharepoint Server
    Sharepoint Consulting
    Sharepoint Designer
    Sharepoint 2010
    Sharepoint services
    Sharepoint site
    Sharepoint devloper

    ReplyDelete
  31. Nick Bathla, owner of YO! Creations, began as a search engine optimizer, digital marketing consultant quickly discovered he had a sixth sense for marketing. Nick decided to launch his own company.

    SearchEngineOptimization
    Search engine Marketing
    Facebook Marketing
    Social Media Marketing
    Facebook Store
    Online Marketing
    Online Advertising
    Internet Marketing
    SEO
    SEM

    ReplyDelete
  32. Running windows applications on Android, Running windows applications on I pad &
    SAP on cloud by Adapt Software India.
    AshishKamotra, Chief Executive Officer, Running windows applications on Android, Running windows applications on I pad by Software India Pvt. Ltd., India Soft-2012, HICC, Hyderabad, Andhra Pradesh. Adapt specializes in SAP on cloud Microsoft Dynamics CRM, Sage CRM, Microsoft .Net, MS SQL & Power Builder.

    SAP on cloud
    Running windows applications on iPad
    Running windows applications on Android
    Go-Global
    Remote access software

    ReplyDelete
  33. What is SharePoint, Microsoft Sharepoint 2013,and Microsoft Sharepoint 2010, Sharepoint Consulting.

    Best Case Studies of Document Management System implementations by Adapt India Software Private Limited,
    Document Management Solution on Microsoft SharePoint to automate your business processes and facilitate exchange of documents and information internallyand with your Sub Contractors with pre- defined workflows triggered with approvals, authorizations ,co-authorizations and authentications.

    Document Management Solution

    Sharepoint
    Sharepoint 2013
    Document Management
    Sharepoint Server
    Sharepoint Consulting
    Sharepoint Designer
    Sharepoint 2010
    Sharepoint services
    Sharepoint site
    Sharepoint devloper

    ReplyDelete
  34. Running windows applications on Android, Running windows applications on I pad &
    SAP on cloud by Adapt Software India.
    AshishKamotra, Chief Executive Officer, Running windows applications on Android, Running windows applications on I pad by Software India Pvt. Ltd., India Soft-2012, HICC, Hyderabad, Andhra Pradesh. Adapt specializes in SAP on cloud Microsoft Dynamics CRM, Sage CRM, Microsoft .Net, MS SQL & Power Builder.

    SAP on cloud
    Running windows applications on iPad
    Running windows applications on Android
    Go-Global
    Remote access software

    ReplyDelete
  35. Local internet marketing & Business Consulting
    The Volpé Consortium, Inc. is an independent business consulting and project management firm specializing in the areas of Business Operations, Project Management, Technology Solutions, and Training. Since our founding, our mission has been to partner with clients to integrate conflict-free consulting and deep subject matter expertise for senior management, resulting in sustainable solutions to complex business challenges.Our services have been proven to drive success across multiple industries and business disciplines. Please use the menu system on this web site to navigate our services portfolio.

    local internet marketing
    internet marketing blog

    ReplyDelete
  36. Local internet marketing & Business Consulting
    The Volpé Consortium, Inc. is an independent business consulting and project management firm specializing in the areas of Business Operations, Project Management, Technology Solutions, and Training. Since our founding, our mission has been to partner with clients to integrate conflict-free consulting and deep subject matter expertise for senior management, resulting in sustainable solutions to complex business challenges.Our services have been proven to drive success across multiple industries and business disciplines. Please use the menu system on this web site to navigate our services portfolio.

    local internet marketing
    internet marketing blog

    ReplyDelete
  37. Local internet marketing & Business Consulting
    The Volpé Consortium, Inc. is an independent business consulting and project management firm specializing in the areas of Business Operations, Project Management, Technology Solutions, and Training. Since our founding, our mission has been to partner with clients to integrate conflict-free consulting and deep subject matter expertise for senior management, resulting in sustainable solutions to complex business challenges.Our services have been proven to drive success across multiple industries and business disciplines. Please use the menu system on this web site to navigate our services portfolio.

    local internet marketing
    internet marketing blog

    ReplyDelete
  38. SAP on cloud and Running windows applications on iPad Specialist.
    AshishKamotra, Chief Executive Officer, Running windows applications on Android, SAP on cloud, running windows applications on Ipad by Software India Pvt. Ltd., India Soft-2012, HICC, Hyderabad, Andhra Pradesh.
    SAP on cloud
    Running windows applications on iPad
    Running windows applications on Android
    Go-Global
    Remote access software

    ReplyDelete
  39. What is SharePoint, Microsoft Sharepoint 2013,and Microsoft Sharepoint 2010, Sharepoint Consulting.

    Best Case Studies of Document Management System implementations by Adapt India Software Private Limited,
    Document Management Solution on Microsoft SharePoint to automate your business processes and facilitate exchange of documents and information internallyand with your Sub Contractors with pre- defined workflows triggered with approvals, authorizations ,co-authorizations and authentications.

    Document Management Solution

    Sharepoint
    Sharepoint 2013
    Document Management
    Sharepoint Server
    Sharepoint Consulting
    Sharepoint Designer
    Sharepoint 2010
    Sharepoint services
    Sharepoint site
    Sharepoint devloper

    ReplyDelete
  40. What is SharePoint, Microsoft Sharepoint 2013,and Microsoft Sharepoint 2010, Sharepoint Consulting.

    Best Case Studies of Document Management System implementations by Adapt India Software Private Limited,
    Document Management Solution on Microsoft SharePoint to automate your business processes and facilitate exchange of documents and information internallyand with your Sub Contractors with pre- defined workflows triggered with approvals, authorizations ,co-authorizations and authentications.

    Document Management Solution

    Sharepoint
    Sharepoint 2013
    Document Management
    Sharepoint Server
    Sharepoint Consulting
    Sharepoint Designer
    Sharepoint 2010
    Sharepoint services
    Sharepoint site
    Sharepoint devloper

    ReplyDelete
  41. What is SharePoint, Microsoft Sharepoint 2013,and Microsoft Sharepoint 2010, Sharepoint Consulting.

    Best Case Studies of Document Management System implementations by Adapt India Software Private Limited,
    Document Management Solution on Microsoft SharePoint to automate your business processes and facilitate exchange of documents and information internallyand with your Sub Contractors with pre- defined workflows triggered with approvals, authorizations ,co-authorizations and authentications.

    Document Management Solution

    Sharepoint
    Sharepoint 2013
    Document Management
    Sharepoint Server
    Sharepoint Consulting
    Sharepoint Designer
    Sharepoint 2010
    Sharepoint services
    Sharepoint site
    Sharepoint devloper

    ReplyDelete
  42. Local internet marketing & Business Consulting
    The Volpé Consortium, Inc. is an independent business consulting and project management firm specializing in the areas of Business Operations, Project Management, Technology Solutions, and Training. Since our founding, our mission has been to partner with clients to integrate conflict-free consulting and deep subject matter expertise for senior management, resulting in sustainable solutions to complex business challenges.Our services have been proven to drive success across multiple industries and business disciplines. Please use the menu system on this web site to navigate our services portfolio.

    local internet marketing
    internet marketing blog

    ReplyDelete
  43. Local internet marketing & Business Consulting
    The Volpé Consortium, Inc. is an independent business consulting and project management firm specializing in the areas of Business Operations, Project Management, Technology Solutions, and Training. Since our founding, our mission has been to partner with clients to integrate conflict-free consulting and deep subject matter expertise for senior management, resulting in sustainable solutions to complex business challenges.Our services have been proven to drive success across multiple industries and business disciplines. Please use the menu system on this web site to navigate our services portfolio.

    local internet marketing
    internet marketing blog

    ReplyDelete
  44. Running windows applications on Android, Running windows applications on I pad &
    SAP on cloud by Adapt Software India.
    AshishKamotra, Chief Executive Officer, Running windows applications on Android, Running windows applications on I pad by Software India Pvt. Ltd., India Soft-2012, HICC, Hyderabad, Andhra Pradesh. Adapt specializes in SAP on cloud Microsoft Dynamics CRM, Sage CRM, Microsoft .Net, MS SQL & Power Builder.

    SAP on cloud
    Running windows applications on iPad
    Go-Global
    Remote access software

    ReplyDelete
  45. Your article helped me to understand the topic well and I would love to share this to my friends. I also love to
    Get Likes for your website
    Thank you for this and all the best.

    ReplyDelete
  46. What is SharePoint, Microsoft Sharepoint 2013,and Microsoft Sharepoint 2010, Sharepoint Consulting.

    Best Case Studies of Document Management System implementations by Adapt India Software Private Limited,
    Document Management Solution on Microsoft SharePoint to automate your business processes and facilitate exchange of documents and information internallyand with your Sub Contractors with pre- defined workflows triggered with approvals, authorizations ,co-authorizations and authentications.

    Document Management Solution

    Sharepoint
    Sharepoint 2013
    Document Management
    Sharepoint Server
    Sharepoint Consulting
    Sharepoint Designer
    Sharepoint 2010
    Sharepoint services
    Sharepoint site
    Sharepoint devloper

    ReplyDelete
  47. Running windows applications on Android, Running windows applications on I pad &
    SAP on cloud by Adapt Software India.
    AshishKamotra, Chief Executive Officer, Running windows applications on Android, Running windows applications on I pad by Software India Pvt. Ltd., India Soft-2012, HICC, Hyderabad, Andhra Pradesh. Adapt specializes in SAP on cloud Microsoft Dynamics CRM, Sage CRM, Microsoft .Net, MS SQL & Power Builder.
    SAP on cloud
    Go-Global
    Remote access software

    ReplyDelete
  48. Running windows applications on Android,Running windows applications onI pad&
    SAP on cloudby Adapt Software India.
    AshishKamotra, Chief Executive Officer, Running windows applications on Android,Running windows applications onI pad by Software India Pvt. Ltd., India Soft-2012, HICC, Hyderabad, Andhra Pradesh. Adapt specializes in SAP on cloud Microsoft Dynamics CRM, Sage CRM, Microsoft .Net, MS SQL & Power Builder.
    Go-Global
    Remote access software
    SAP on cloud
    Tally on cloud
    Navision on cloud
    web enabling software in india

    ReplyDelete
  49. Nick Bathla, owner of YO! Creations, began as a search engine optimizer, digital marketing consultant quickly discovered he had a sixth sense for marketing. Nick decided to launch his own company.
    He is providing Search Engine Optimization
    Search engine Marketing, Facebook Marketing,Social Media Marketing, Facebook Store,Online Marketing, Online Advertising,Internet Marketing,SEO, SEM.

    SearchEngineOptimization
    Search engine Marketing
    Facebook Marketing
    Social Media Marketing
    Facebook Store
    Online Marketing
    Online Advertising
    Internet Marketing
    SEO
    SEM


    ReplyDelete
  50. Running windows applications on Android, Running windows applications on Ipad&
    SAP on cloud by Adapt Software India.

    Go-Global
    Remote access software

    ReplyDelete
  51. SAP on cloud by Adapt Software India. Ashish Kamotra, Chief Executive Officer, Running windows applications on Android, Running windows applications on Ipad by Software India Pvt. Ltd., India Soft-2012, HICC, Hyderabad, Andhra Pradesh. Adapt specializes in SAP on cloud Microsoft Dynamics CRM, Sage CRM, Microsoft .Net, MS SQL & Power Builder.
    Go-Global
    Remote access software
    SAP on cloud
    Tally on cloud
    Navision on cloud
    web enabling software in india

    ReplyDelete
  52. What is SharePoint, Microsoft Sharepoint 2013,and Microsoft Sharepoint 2010, Sharepoint Consulting.

    Best Case Studies of Document Management System implementations by Adapt India Software Private Limited,
    Document Management Solution on Microsoft SharePoint to automate your business processes and facilitate exchange of documents and information internally and with your Sub Contractors with pre- defined workflows triggered with approvals, authorizations ,co-authorizations and authentications.



    Sharepoint
    Sharepoint 2013
    Document Management
    Sharepoint Server
    Sharepoint Consulting
    Sharepoint Designer
    Sharepoint 2010
    Sharepoint services
    Sharepoint site
    Sharepoint developer

    ReplyDelete
  53. What is SharePoint, Microsoft Sharepoint 2013,and Microsoft Sharepoint 2010, Sharepoint Consulting.

    Best Case Studies of Document Management System implementations by Adapt India Software Private Limited,
    Document Management Solution on Microsoft SharePoint to automate your business processes and facilitate exchange of documents and information internallyand with your Sub Contractors with pre- defined workflows triggered with approvals, authorizations ,co-authorizations and authentications.

    Document Management Solution

    Sharepoint
    Sharepoint 2013
    Document Management
    Sharepoint Server
    Sharepoint Consulting
    Sharepoint Designer
    Sharepoint 2010
    Sharepoint services
    Sharepoint site
    Sharepoint developer

    ReplyDelete
  54. Go-Global , Running windows applications on Android, Running windows applications on I pad.
    SAP on cloud by Adapt Software India. Ashish Kamotra, Chief Executive Officer, Running windows applications on Android, Running windows applications on Ipad by Software India Pvt. Ltd., India Soft-2012, HICC, Hyderabad, Andhra Pradesh. Adapt specializes in SAP on cloud Microsoft Dynamics CRM, Sage CRM, Microsoft .Net, MS SQL & Power Builder.
    Go-Global
    Remote access software
    SAP on cloud
    Tally on cloud
    Navision on cloud
    web enabling software in india

    ReplyDelete
  55. Thank you for another essential article. Where else could anyone get that kind of information in such a complete way of writing? I have a presentation incoming week, and I am on the lookout for such information.

    ReplyDelete