Facebook worm: caution circulates PoC

PoC for Facebook Worm: A Polish security researcher today published a PoC that could be used to create a fully functional Facebook worm.

The code exploits a security hole in Facebook's platform. The researcher who alias Lasq, discovered the vulnerability when he noticed it was being used by spammers on Facebook.Facebook

The vulnerability is in the mobile application version. The computer version is unaffected.

Lasq reports that vulnerability allows clickjacking and that an attacker can exploit it through iframes.

Lasq explains:

Yesterday I noticed a very annoying SPAM campaign on Facebook, where many of my friends posted a link to a site hosted on an AWS bucket. There was also a link to a French site with funny comic books.

Once you clicked on the link, the page hosted on the AWS bucket was displayed, asking you to verify that you are 16 years old or older (in French) to access the content. Once you clicked the button, your page was promoted to a funny comic (and many ads) page. However, in the meantime the same link you just pressed automatically posted on your Facebook wall.

The researcher watched the subject and noticed that he was completely oblivious to it security “X-Frame-Options.” This header is used by websites to prevent page code from loading through iframes and is a primary defense against clickjacking attacks.

Lasq said he announced the problem on Facebook, but the company refused to correct it. So he decided to publish the PoC.

Lasq's code doesn't include the clickjacking part, the one that posts content to victims' walls, but if you're interested and want to find it, it's on the with a simple . Ο κώδικας του Lasq επιτρέπει μόνο σε έναν εισβολέα να φορτώσει και να εκτελέσει μη εξουσιοδοτημένο κώδικα σε κάποιο λογαριασμό χρήστη του Facebook.

___________

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).