IT Security

Share your knowledge & discuss all aspects of Computer & Internet Security via a worldwide community.

jeudi 29 décembre 2016

CLEVER FACEBOOK HACK REVEALS PRIVATE EMAIL ADDRESS OF ANY USER



Facebook Transparency Report











Christmas came early for Facebook bug bounty hunter Tommy DeVoss who was paid $5,000 this week for discovering a security vulnerability that allowed him to view the private email addresses of any Facebook user.
“The hack allowed me to harvest as many email addresses as I wanted from anybody on Facebook,” DeVoss said. “It didn’t matter how private you thought your email address was – I could of grabbed it.”

The bug was tied to the user-generated Facebook Groups feature that allows any member to create an affinity group on the social network’s platform. DeVoss discovered as an administrator of a Facebook Group he could invite any Facebook member to have Admin Roles via Facebook’s system to do things such as edit post or add new members.
DeVoss said on Thanksgiving Day he discovered the vulnerability and reported it to Facebook via itsbug bounty program. After weeks of going back and forth verifying what the exact bug was and how it was exploited, Facebook said it would award him $5,000 for the discovery. And on Tuesday it did.
Those invitations were handled by Facebook and sent to the invited recipient’s Facebook Messages inbox, but also to the Facebook user’s email address associated with their account. In many cases users choose to keep their email addresses private. DeVoss discovered, despite privacy settings set by Facebook members, he was able to gain access to any Facebook user’s email address whether he was Friends with them or not.
DeVoss found when he cancelled pending invitations to those invited to be Facebook Group Administrators there was a glitch. “While Facebook waits for the confirmation, the user is forwarded to a Page Roles tab that includes a button to cancel the request,” he said.
Next, he switched to Facebook’s mobile view of the Page Roles tab. Here DeVoss was able to view the full email addresses of anyone he wanted to cancel from becoming a Facebook Group Administrator.
“I noticed that when you clicked to cancel the administrator invitation on the mobile page, you were redirected to a page with the email address in the URL,” he said. “Now all you have to do is pluck the plaintext version of the confidential email address straight from the URL.”
The impact of this vulnerability could be diverse, he wrote in a blog post outlining his discovery. “Harvesting email addresses this way contradicts Facebook’s privacy policy and could lead to targeted phishing attempts or other malicious purposes.”
Facebook confirmed the hack and said it has no evidence the vulnerability was ever misused. Facebook said it has implemented a fix to prevent the issue from being exploited.
DeVoss, a software developer in Virginia, said this is the largest bug bounty payment he has ever earned. He told Threatpost he participates in a number of bug bounty programs including Yahoo’s and the Hack the Pentagon program.
For its part, in October Facebook announced it has paid out more than $5 million to 900 researchers in the five years since it implemented its bug bounty program. The company said it paid out $611,741 to 149 researchers in the first half of 2016 alone.
Facebook was one of the first websites to launch a bug program when it followed in the footsteps of both Mozilla and Google in August 2011. In February, the company paid $10,000 to a 10-year-old boy from Finland after he discovered an API bug in the image sharing app Instagram, which Facebook bought for $1B in 2012. The company awarded $15,000 to Anand Prakash in March for a bug allowed him to crack open any of Facebook’s 1.1 billion accounts using a rudimentary brute force password attack.
Publié par Unknown à 19:01
Envoyer par e-mailBlogThis!Partager sur XPartager sur FacebookPartager sur Pinterest
Libellés : email hack, hacking facebook, user email

Aucun commentaire:

Enregistrer un commentaire

Article plus récent Article plus ancien Accueil
Inscription à : Publier les commentaires (Atom)

Earn Bitcoin

BTCClicks.com Banner

IP Info

Powered by Find-IP.net

Live Traffic IT Security

Rechercher dans IT Security

Qui êtes-vous ?

Unknown
Afficher mon profil complet

Translate Blog

Archives du blog

  • ►  2017 (7)
    • ►  juin (1)
    • ►  mai (2)
    • ►  février (1)
    • ►  janvier (3)
  • ▼  2016 (219)
    • ▼  décembre (219)
      • CLEVER FACEBOOK HACK REVEALS PRIVATE EMAIL ADDRESS...
      • Knock-Knock writeup
      • SECURITYSOFTVIEW - DISPLAYS THE ANTIVIRUS / ANTISP...
      • SECURITY ONION - LINUX DISTRO FOR INTRUSION DETECT...
      • SECURITY CHEATSHEETS - A COLLECTION OF CHEATSHEETS...
      • RUBOCOP - A RUBY STATIC CODE ANALYZER, BASED ON TH...
      • ROUTERCHECK - ANDROID APP FOR ENSURE THE SAFETY OF...
      • REXT - ROUTER EXPLOITATION TOOLKIT
      • REMOTE DLL INJECTOR V2.0 - COMMAND-LINE TOOL TO IN...
      • REMNUX V6 - A LINUX TOOLKIT FOR REVERSE-ENGINEERIN...
      • REKALL - THE MOST COMPLETE MEMORY ANALYSIS FRAMEWORK
      • RAWR - RAPID ASSESSMENT OF WEB RESOURCES
      • QARK - TOOL TO LOOK FOR SEVERAL SECURITY RELATED A...
      • Q-SHELL - QUICK SHELL FOR UNIX ADMINISTRATOR
      • PYPHISHER - A SIMPLE PYTHON TOOL FOR PHISHING
      • PYERSINIA - NETWORK ATTACK TOOL
      • PUPY - MULTI-PLATFORM REMOTE ADMINISTRATION TOOL
      • PROXYDROID - SET PROXYS (HTTP / SOCKS4 / SOCKS5) O...
      • PROXENET - HACKER FRIENDLY PROXY FOR WEB APPLICATI...
      • PROJECT ARTILLERY - FULL SUITE FOR PROTECTION AGAI...
      • PROGUARD - JAVA CLASS FILE SHRINKER, OPTIMIZER, OB...
      • POWERTOOLS - COLLECTION OF POWERSHELL PROJECTS WIT...
      • POWERCAT - NETCAT: THE POWERSHELL VERSION
      • PORTEXPERT - MONITORS ALL APPLICATIONS CONNECTED T...
      • PORTEXPERT - MONITORS ALL APPLICATIONS CONNECTED T...
      • PORTEXPERT - MONITORS ALL APPLICATIONS CONNECTED T...
      • PORTDOG - SIMPLE PYTHON SCRIPT TO DETECT PORT SCAN...
      • POET - A SIMPLE POST-EXPLOITATION TOOL
      • PLECOST - WORDPRESS VULNERABILITIES FINDER
      • PIXIEWPS - BRUTEFORCE OFFLINE THE WPS PIN (PIXIE D...
      • PHEMAIL - AUTOMATE SENDING PHISHING EMAILS
      • PHAN - STATIC ANALYZER FOR PHP
      • PENTOO 2015 - SECURITY-FOCUSED LIVECD BASED ON GENTOO
      • PENTESTPACKAGE - A PACKAGE OF MULTIPLE PENTEST SCR...
      • PENTESTBOX - PORTABLE PENETRATION TESTING DISTRIBU...
      • PEMCRACKER - TOOL TO CRACK ENCRYPTED PEM FILES
      • PEINJECTOR - MITM PE FILE INFECTOR
      • PEFRAME - TOOL TO PERFORM STATIC ANALYSIS ON PORTA...
      • PASSWORD SNIFFER CONSOLE - COMMAND-LINE TOOL TO SN...
      • PASSWORD CRACKING SUITE
      • PASSGEN - RANDOM CHARACTER GENERATOR CRUNCH TO CRA...
      • PACKETH - ETHERNET PACKET GENERATOR
      • PACKET SENDER - THE UDP AND TCP NETWORK TEST UTILITY
      • OWASP ZSC SHELLCODER - GENERATE CUSTOMIZED SHELLCODES
      • OWASP ZAP 2.4.1 - PENETRATION TESTING TOOL FOR TES...
      • OWASP ZAP 2.4.0 - PENETRATION TESTING TOOL FOR TES...
      • OPENVAS - THE WORLD'S MOST ADVANCED OPEN SOURCE VU...
      • OCLHASHCAT V2.01 - WORLDS FASTEST PASSWORD CRACKER
      • NSEARCH - NMAP SCRIPT ENGINE SEARCH
      • NORIBEN - YOUR PERSONAL, PORTABLE MALWARE SANDBOX
      • NOPO - NOSQL HONEYPOT FRAMEWORK
      • NMAP 7 - SECURITY SCANNER FOR NETWORK EXPLORATION ...
      • NIPPER - TOOLKIT WEB SCAN FOR ANDROID
      • NIPE - SCRIPT TO REDIRECT ALL TRAFFIC FROM THE MAC...
      • NIKTO2 - WEB SERVER SCANNER
      • NETSPARKER CLOUD - ONLINE WEB APPLICATION SECURITY...
      • NETSPARKER 4 - EASIER TO USE, MORE AUTOMATION AND ...
      • NETRIPPER - SMART TRAFFIC SNIFFING FOR PENETRATION...
      • NETOOL.SH - MITM PENTESTING OPENSOURCE T00LKIT
      • NET-CREDS - SNIFF PASSWORDS AND HASHES FROM AN INT...
      • MYSQL QUERY BROWSER PASSWORD DUMP - COMMAND-LINE T...
      • MPC - MSFVENOM PAYLOAD CREATOR
      • MOSCA - STATIC ANALYSIS TOOL TO FIND BUGS
      • MOBSF (MOBILE SECURITY FRAMEWORK) - MOBILE (ANDROI...
      • MOBAXTERM - TERMINAL FOR WINDOWS WITH X11 SERVER, ...
      • MITMF - FRAMEWORK FOR MAN-IN-THE-MIDDLE ATTACKS
      • MICENUM - MANDATORY INTEGRITY CONTROL ENUMERATOR F...
      • METASPLOIT AV EVASION - METASPLOIT PAYLOAD GENERAT...
      • MEDUSA - SPEEDY, PARALLEL AND MODULAR LOGIN BRUTE-...
      • MASSBLEED - MASS SSL VULNERABILITY SCANNER
      • MALWARE - MALWARE REPOSITORY FRAMEWORK
      • MALIGNO V2.0 - METASPLOIT PAYLOAD SERVER
      • MALHEUR - AUTOMATIC ANALYSIS OF MALWARE BEHAVIOR
      • LYNIS 2.1.1 - SECURITY AUDITING TOOL FOR UNIX/LINU...
      • LYNIS 2.1.0 - SECURITY AUDITING TOOL FOR UNIX/LINU...
      • LYNIS 2.0.0 - SECURITY AUDITING TOOL FOR UNIX/LINU...
      • LUKS-OPS - AUTOMATE THE USAGE OF LUKS VOLUMES IN L...
      • LOKI - SCANNER FOR SIMPLE INDICATORS OF COMPROMISE
      • LMD - LINUX MALWARE DETECT
      • LINSET - WPA/WPA2 HACK WITHOUT BRUTE FORCE
      • LIME - LINUX MEMORY EXTRACTOR
      • KUNAI - PWNING & INFO GATHERING VIA USER BROWSER
      • KING PHISHER - PHISHING CAMPAIGN TOOLKIT
      • KEYBOX - A WEB-BASED SSH CONSOLE THAT CENTRALLY MA...
      • KEEFARCE - EXTRACTS PASSWORDS FROM A KEEPASS 2.X D...
      • KATOOLIN - AUTOMATICALLY INSTALL ALL KALI LINUX TOOLS
      • KATANA - FRAMEWORK FOR HACKERS, PROFESSIONAL SECUR...
      • KALI LINUX NETHUNTER - ANDROID PENETRATION TESTING...
      • KALI LINUX 2.0 - THE BEST PENETRATION TESTING DIST...
      • KALI LINUX 1.1.0 - THE BEST PENETRATION TESTING DI...
      • KADIMUS - LFI SCAN & EXPLOIT TOOL
      • JUST-METADATA - TOOL THAT GATHERS AND ANALYZES MET...
      • JSQL INJECTION V0.73 - JAVA TOOL FOR AUTOMATIC SQL...
      • JOOMLAVS - A BLACK BOX, JOOMLA VULNERABILITY SCANNER
      • JOHNNY - GUI FOR JOHN THE RIPPER
      • JEXBOSS - JBOSS VERIFY AND EXPLOITATION TOOL
      • JAVA LOIC - LOW ORBIT ION CANNON. A JAVA BASED NET...
      • JADX - JAVA SOURCE CODE FROM ANDROID DEX AND APK F...
      • IVRE - A PYTHON NETWORK RECON FRAMEWORK, BASED ON ...
      • IP THIEF - SIMPLE IP STEALER IN PHP
COPYRIGHT © IT Security . Thème Picture Window. Fourni par Blogger.