Facebook worm: caution circulates PoC

PoC for Facebook Worm: A Polish security researcher today published a PoC that could be used to create a fully functional Facebook worm.

The code exploits a security gap on the Facebook platform. The investigator using the Lasq alias discovered the vulnerability when he noticed that spammers used it on Facebook.Facebook

The vulnerability lies in the of the mobile application. The desktop version is not affected.

Lasq reports that vulnerability allows clickjacking and that an attacker can exploit it through iframes.

Lasq explains:

Yesterday I noticed a very annoying SPAM campaign on Facebook where many of my friends were posting a link to a site hosted on some AWS . There was also a link to a French site with funny comics.

After clicking the link, the page hosted on the AWS bucket appeared, asking you to verify that you are 16 or older (in French) to get στο περιεχόμενο. Αφού κάνατε κλικ στο , η σελίδα σας προωθούσε σε μια σελίδα με αστεία κόμικ (και πολλές διαφημίσεις). Ωστόσο, στο μεταξύ ο ίδιος σύνδεσμος που μόλις πατήσατε δημοσίευσε αυτόματα και στον τοίχο σας στο Facebook.

The researcher followed the issue and noticed that he was completely unaware of the security header "X-Frame-Options." This header is used by websites to prevent page code from loading through iframes and is a primary protection against clickjacking attacks.

Lasq said he announced the problem on Facebook, but the company refused to correct it. So he decided to publish the PoC.

Lasq's code does not include the part of clickjacking, which publishes content on the walls of the victims, but if you are interested and want to find it there is on the internet with a simple search. Lasq's code only allows an attacker to load and run unauthorized code on a Facebook user account.

___________

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).