How to View Every Message From Facebook Messenger

Facebook has managed to fix a serious vulnerability in Messenger Messenger on the Web but also on mobile versions. Vulnerability allowed attackers to see, edit, or delete any conversation.

Investigator Roman Zaikin of Check Point was the one who discovered the vulnerability since the beginning of the month, and Facebook immediately released updates to address the problem.Messenger

According to Zaikin, the vulnerability was based on how Facebook Messenger works. Every conversation from the app of messages between two users, is transmitted through the Facebook servers. Each message has a random message_id that is unique for each message.

Zaikin realized that using the facebook.com/ajax/mercury/thread_info.php URL, he could find out the ID of each message.

The only requirement was that the attacker has some way to log in and store the message request. This can be done through proxy servers, or by infected ones of the user with some malware that will record these message requests and then send them to the hacker's server.

Assuming the attacker has gotten hold of the message_ids, Zaikin developed an automated attack that sends messages with the same ID by rewriting the of the original message.

Since the mobile version of Messenger allows users to delete messages, automated attack can also be used to delete existing messages.

Attack is extremely risky because it allows spammers to continually update their messages with updated malicious URLs, in case their original servers are shut down.

Furthermore, since chat logs are admissible as evidence in court, an attacker could also modify existing conversations to shift blame to another person, or erase all traces of wrongdoing altogether.

Below is a video from Raikin that shows the vulnerability of Facebook Messenger:

 

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).