Reconnect Facebook's vulnerability allows account hijacking

Security expert Egor Homakov from Sakurity the Reconnect tool was released (Reconnection) that allows hackers to exploit a Facebook vulnerability to breach accounts on websites that use the "connect to Facebook" feature.Reconnect tool Faceboook

Homakov, working for the Sakurity pentesting company, reported a Facebook vulnerability a year ago, but the company did not update its code to protect a huge number of websites using the feature.

The exploits cross-site flaws forgery (CSRF) affecting Facebook Login, which allows users to connect to third-party websites through their Facebook accounts. Basically the vulnerability allows attackers to gain access to victims' accounts using Facebook apps developed by third-party websites such as Mashable, Vimeo, About.me, Stumbleupon and many others.

"The Reconnect is a ready-to-use tool to hack website accounts that use Facebook Login, for example Booking.com, , About.me, Stumbleupon, Angel.co, Mashable.com, Vimeo and many more,” Homakov wrote in a post on blog of his company.

Egor Homakov @ Sakurity
"You are free to copy and modify the source code of the tool. Facebook refused to fix this issue a year ago, unfortunately, it's time for blackhats to get the tool. "

Facebook, on the other hand, declined to accept the attack, blaming the developers who do not follow Facebook's best practices.

To put it another way, the did not fix the vulnerability because the researcher did not follow Facebook's procedure to the letter.

Until the company fixes the problem, websites that use Facebook Login can disable the service from their sites.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).