Showing posts with label White Hat. Show all posts
Showing posts with label White Hat. Show all posts

Monday, August 19, 2013

How's this for irony? Mark Zuckerberg's wall got hacked....warning him of a security problem.

A Palestinian IT expert who claimed to have discovered a Facebook vulnerability said he took his bug report to Mark Zuckerberg's Facebook page after being ignored by the social network's security team.

The vulnerability allows anyone to post anything to anyone else's page, regardless of whether they are a Facebook friend of that person, Khalil Shreateh wrote in a blog post Saturday. Shreateh initially reported the vulnerability through Facebook's "white hat" security disclosure service, which offers a minimum bounty of $500 for legitimate bugs.

However, despite including a demonstration of the bug executed on the Facebook page of Zuckerberg pal Sarah Goodwin, Shreateh was told by a Facebook security engineer in a terse note that "sorry this is not a bug."

Undaunted, Shreateh decided to share his experience with Zuckerberg by posting a note to the Facebook founder's page that apologized for the post but said he had "no other choice."

"[A] couple of days ago I discovered a serious Facebook exploit that allows users to post to other Facebook users timeline while they are not in friend list," Shreateh wrote in his post to Zuckerberg's timeline. "I appreciate your time reading this and getting some one from your company team to contact me."

Within minutes, Shreateh was contacted by a Facebook security seeking details of the exploit, Shreateh said, adding that his own Facebook account was quickly disabled. A security engineer told Shreateh his account had been disabled as a "precaution."

"When we discovered your activity we did not fully know what was happening," an engineer who identified himself as "Joshua" told Shreateh. "Unfortunately your report to our Whitehat system did not have enough technical information for us to take action on it. We cannot respond to reports which do not contain enough detail to allow us to reproduce an issue."

Joshua also informed Shreateh that he would not be receiving a bug reward for reporting the exploit because he violated the site's terms of service. "We do hope, however, that you continue to work with us to find vulnerabilities in the site," he wrote.

A Facebook security engineer responded Saturday in a Hacker News post that the vulnerability was fixed Thursday and conceded that Shreateh should have been asked for more details on the issue after his initial report. Along with offering inadequate information about the bug, Shreateh's post to Zuckerberg's timeline violated the social network's responsible disclosure policy, the security engineer wrote.

"Exploiting bugs to impact real users is not acceptable behavior for a white hat," the engineer wrote, adding that researchers are allowed to create test accounts to aid their research.


(click for larger screen shot)
Source: CNET

Tuesday, July 2, 2013

Low on money? Know how to hack? Get on over to Facebook to "research" (a.k.a. hack).

Facebook has paid a $20,000 reward to a UK based security researcher for reporting a bug that hackers could've used to take over users' accounts. 

Last month, UK security researcher Jack Whitton found a way to hack into other users' Facebook accounts without their knowledge, simply by sending a text message to Facebook. 

The flaw, which Facebook has fixed, was in a Facebook service that lets users link their mobile phones with their accounts. This lets them log into Facebook using their phone number instead of their email address, and send profile updates via text message.

To activate this feature, a user sends a text message to Facebook, which texts back an authorization code. This code is what ties the user's device to their account. 

But Whitton found that Facebook's authorization code could be tweaked to work with other users accounts as well. This means a hacker could just change the password and gain complete control over the account.

Graham Cluely, an independent security analyst, says the bug could have had a widespread impact on Facebook users.

"This should – obviously – have been impossible, but due to a weakness in Facebook’s tangled nest of millions and millions of lines in code, potentially hundreds of millions of accounts were vulnerable to hijacking through the simple technique," Cluely said in a Friday blog post.

Whitton informed Facebook about the flaw May 23, and Facebook fixed it five days later. Facebook gave Whitton a shout-out on its list of "white hats," the term for researchers who find bugs and inform vendors instead of using them for financial gain.

Source:  Business Insider

Saturday, June 22, 2013

New Facebook bug exposes some contact information.

A newly discovered Facebook bug may have inadvertently compromised the contact information of 6 million users, the company says.

The bug, which has since been repaired, was part of the Download Your Information tool, which lets Facebook users export all the data from profiles, such as posts to their timeline and conversations with friends. People using the tool may have downloaded inadvertently the contact information for people they were somehow connected to.
 
Some people upload their contact lists or address books to Facebook, which the company then uses to suggest new friends they can connect with who are already using the service.
 
Though the number of people impacted is sizable, the actual spread of their contact information appears to be limited. The phone numbers and e-mail addresses were not exposed to developers or posted publicly. It is only shown to people they had at least a tentative connection with, and who may have already had their contact information. Even in that pool, it was only exposed to people who had used the data-exporting tool.

"For almost all of the email addresses or telephone numbers impacted, each individual email address or telephone number was only included in a download once or twice. This means, in almost all cases, an email address or telephone number was only exposed to one person," Facebook's security team said in a post.
 
The company says it has no evidence that the bug was "exploited maliciously" and that there have been no complaints so far.
 
The social media company announced the bug on Friday afternoon. The issue was discovered by a third-party security researcher who submitted it through Facebook's White Hat program.
 
Facebook's White Hat program is set up so that people such as security researchers can report any vulnerabilities they find on the social network and get a reward for $500 and up in return. These types of programs are common at Internet companies.
 
"Your trust is the most important asset we have, and we are committed to improving our safety procedures and keeping your information safe and secure," read the post.
People who were affected by the bug will receive an e-mail from Facebook.
 
Source: CNN