• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / News / Facebook worm: caution circulates PoC

Facebook worm: caution circulates PoC

22/12/2018 14:34 by giorgos

PoC for Facebook Worm: A Polish security researcher today published a PoC that could be used to create a fully functional Facebook worm.

The code exploits a security gap on the Facebook platform. The investigator using the Lasq alias discovered the vulnerability when he noticed that spammers used it on Facebook.facebook sec - Facebook worm: attention released PoC

The vulnerability is in the mobile application version. The computer version is unaffected.

Lasq reports that vulnerability allows clickjacking and that an attacker can exploit it through iframes.

Lasq explains:

Yesterday I noticed a very annoying SPAM campaign on Facebook, where many of my friends posted a link to a site hosted on an AWS bucket. There was also a link to a French site with funny comic books.

Once you clicked on the link, the page hosted on the AWS bucket was displayed, asking you to verify that you are 16 years old or older (in French) to access the content. Once you clicked the button, your page was promoted to a funny comic (and many ads) page. However, in the meantime the same link you just pressed automatically posted on your Facebook wall.

The researcher followed the issue and noticed that he was completely unaware of the security header "X-Frame-Options." This header is used by websites to prevent page code from loading through iframes and is a primary protection against clickjacking attacks.

Lasq said he announced the problem on Facebook, but the company refused to correct it. So he decided to publish the PoC.

Lasq's code does not include the part of clickjacking, which publishes content on the walls of the victims, but if you are interested and want to find it there is on the internet with a simple search. Lasq's code only allows an attacker to load and run unauthorized code on a Facebook user account.

___________

  • Old Messages in Facebook return randomly to users
  • LibreOffice 6.1.4 New Release from Document Foundation
  • Facebook Research by DPC for leaked photos
  • Facebook two-factor authentication without phone number
Facebook worm: caution circulates PoC was last modified: 22 December, 2018, 2: 34 mm by giorgos

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: Newstag: authentication, clickjacking, iframe, I'm sure, two-factor

You May Also Like

What is two-factor authentication? Why you should use it
Do you have anything to post? Send it to Your Post
iGuRu about hosting and site changes

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « MX Linux 18 x64 Custom ISO from iGuRu.gr
Next Post: iGuRu.gr 20's top 2018 publications »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.