Reconnect Facebook's vulnerability allows account hijacking

The specialist in τα ασφαλείας Egor Homakov από την εταιρεία Sakurity the Reconnect tool was released (Relink) that allows hackers to exploit a Facebook vulnerability to compromise accounts on websites that use the "connect with Facebook".Reconnect tool Faceboook

Homakov, working for the Sakurity pentesting company, reported a Facebook vulnerability a year ago, but the company did not update its code to protect a huge number of websites using the feature.

The εκμεταλλεύεται ελαττώματα cross-site forgery (CSRF) affecting Facebook Login, which allows users to connect to third-party websites through their Facebook accounts. Basically the vulnerability allows attackers to gain access to victims' accounts using Facebook apps developed by third-party websites such as Mashable, Vimeo, About.me, Stumbleupon and many others.

"The Reconnect is a ready-to-use tool to enter into Facebook accounts using Facebook Login, for example on Booking.com, Bit.ly, About.me, Stumbleupon, Angel.co, Mashable.com, Vimeo and many more, "wrote Homakov in a post at blog of his company.

Egor Homakov @ Sakurity
"You are free to copy and modify the source code of the tool. Facebook refused to fix this issue a year ago, unfortunately, it's time for blackhats to get the tool. "

Facebook, on the other hand, declined to accept the attack, blaming the developers who do not follow Facebook's best practices.

To put it differently, the social network did not correct the vulnerability because the researcher did not follow the word defined by Facebook.

Until the company fixes the problem, websites that use Facebook Login can disable it από τα sites τους.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).