Vodafone Spain admits 3,000 sm...
OOPS! Not something you want to be doing to your customers!

Feds use phony MySpace profile...
As the article suggests there is a certain amount of irony in this.

Tories pledge 'fastest broadba...
Worth a read, we definitely need a better broadband infrastructure

Twitter launches its own URL s...
This seems like a good move form twitter, especially if it reduces the number of scams through the service. Worth a ...

Pennsylvania State fools fire ...
Any Pennsylvania residents? (we have a few) - I feel for you - with people like this deciding on who works for your S...




LeeFisher
Backdoor access to Facebook and MySpace accounts
Posted On : 11/5/2009 4:17:54 PM
Article Rating :
Read : 181 Times
Discussed Within: Security in General (Public)
Tags: Facebook, Myspace, Backdoor
Total Thumbs Up 0    Total Thumbs down 0
http://www.yvoschaap.com/index.php/weblog/faceb...

From the looks of things a Dutch developer, Yvo Schaap (blog link above) stumbled on a back door into any user account that accesses the application he's working on.

He discovered the problem while trying to get around a function limitation on his application and in doing so, realised he could modify the account settings. Even worse - his illegitimate interventions into the account couldn't even be traced!



The crux of the matter?
"Adobe introduced a "crossdomain.xml" file which could allow certain domains accessing another domain, leading to cross domain access by certain or all domains."

Facebook did block access through Flash from any non-facebook domain but this didn't go the whole way. By simply changing the subdomain you can circumvent the barrier and access domain data.

"This wouldn't be a big deal if the subdomain only hosts images, but unfortunately this domain hosts the whole Facebook property, including a facebook user session. If you have auto-login enabled on Facebook, you might recognize your fullname and the keys to do actions from the accounts credentials."

It's not just limited to Facebook, MySpace suffers from the same issue. Yvo continues :

"All what has to happen is an active session, or a "auto login"-cookie and a URL which hosts a exploiting Flash file. For example when accessed, a automatic "post update" could be made, that would lure friends of the user to access the exploit URL, and the exploit would spread virally. An more invasive and hidden exploit could harvest all the users personal photo's, data and messages to a central server without any trace, and there is no reason why this wouldn't be happening already with both Facebook and MySpace data."

Bookmark and Share
Login or Join to add your comment.