facebook hacked

Hacking all Facebook accounts from Android apps

Ο Mohamed Ramadan, a security researcher  from Attack Secure, identified two vulnerabilities in Facebook apps for Android.

One of vulnerabilities affect application versions Facebook and Facebook Messenger always for Android. The security gap allows hackers to steal them token access and through them to gain access to the accounts.

In accordance with Ramadan , the attacker must simply send a στο θύμα που περιέχει ένα συνημμένο – ή σύνδεσμο οποιουδήποτε τύπου, βίντεο , έγγραφο ή και .

When the user downloads the attached file, Facebook access_token is registered in the Android logcat, which is the Android logging system (logs) that provides a system for debugging the system.

Αυτό σημαίνει ότι οποιαδήποτε Android εφαρμογή που έχετε εγκαταστήσει στο smartphone σας μπορεί να αποκτήσει το διακριτικό πρόσβασης σας , και εμμέσως τον on Facebook.

“Every time you use the Facebook app or the Facebook Messenger app to download files from the , your access_token will be leaked and any application, even non-malicious ones, can take these tokens and hack your Facebook account,” the researcher said.

For this vulnerability, the researcher took from Facebook as a reward for the 2500 dollar finding.

The second vulnerability he discovered affects Facebook Manager as well as Pages for Android. The vulnerability is similar to the first.

To demonstrate vulnerability to applications o  Ramadan made a demo and recorded it on video.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).