Facebook vulnerability persists 10 months later

Facebook-Bug-

A security bug reported on at the beginning of the year and allows an attacker to post comments on someone else's Timeline without permission, is still ten months after.

Last year, researcher Vivek Bansal disclosed the vulnerability to Facebook's security team, showing how tokens for mobile apps, can be used to post on a third party's Timeline without necessary permission. (Note that an app cannot "post" text or links to a user's Timeline without "required permission from the account holder")

Vulnerability still exists ten months after (Video)

To indicate this error in Facebook, Bansal, received $ 2.000 fee and was inducted into the Hall of Fame of researchers, who identified seriously in the security mechanisms of the social networking platform. However, it seems that the vulnerability either came back in code changes, or someone forgot to patch it – with the first version being the dominant one.
Recently, Bansal followed the same script he used for the original bug demonstration and noticed that everything worked as if no changes had been made. One που αναρτήθηκε στο YouTube (δείτε παρακάτω) την περασμένη Τρίτη έδειξε ότι η ευπάθεια ήταν ακόμη ενεργή.  Όταν Bansal ερωτήθηκε αν δοκίμασε το σενάριο σε μια πιο πρόσφατη ημερομηνία, προκειμένου να εξακριβώσει εάν εξακολουθεί να να υπάρχει η ευπάθεια, εκείνος απάντησε λέγοντας ότι η πιο πρόσφατη that he did was on monday, and the damage was still present.

It's hard to believe that Facebook paid the researcher, and his technicians forgot to fix the vulnerability - though it's not impossible for that to happen. The most likely scenario, however, is that they forgot to re-examine the patch at a later time. This theory is reinforced by the fact that Bansal received an email from Facebook earlier this year informing him that the vulnerability had been fixed and that he was free to publish his findings. Check out the latest demo of the bug:

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).