Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • PM Modi in Manipur
  • Charlie Kirk killer
  • Sushila Karki
  • IND vs PAK
  • India-US ties
  • New human organ
  • Downton Abbey: The Grand Finale Movie Review
fp-logo
Hacker finds Facebook flaw that exposes private information
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • News & Analysis
  • Hacker finds Facebook flaw that exposes private information

Hacker finds Facebook flaw that exposes private information

Nishtha Kanal • February 26, 2013, 18:00:29 IST
Whatsapp Facebook Twitter

Facebook has found itself engulfed in yet another hacking scandal, only this time, it’s scarier than a simple malware problem. A hacker has been able to…

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
Hacker finds Facebook flaw that exposes private information

Facebook has found itself engulfed in yet another hacking scandal, only this time, it’s scarier than a simple malware problem. A hacker has been able to exploit a major privacy flaw in the social networking giant’s OAuth permissions to access almost anyone’s private data.

Security hacker Nir Goldshlager described his exploits in a blog post, detailing how he went about working through a flaw in the website. The OAuth permission crops up every time an application needs some or all of your information to run smoothly on Facebook. When you hit the ‘Allow’ button on the site, the application gets access to information like your name, your age, your location and more. The app can even seek permission to post on your timeline on your behalf.

STORY CONTINUES BELOW THIS AD

“I found a way in to get a full permissions (read inbox, outbox, manage pages, manage ads, read private photos, videos,etc..) over the victim account even without any installed apps on the victim’s account,” Goldshlager revealed. “By exploiting this flaw I could steal unique access tokens that provides me full control over any Facebook account,” he wrote.

More from News & Analysis
What is the US HIRE Bill and why is India’s $250-billion IT sector worried? What is the US HIRE Bill and why is India’s $250-billion IT sector worried? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true?

cover

Hacked again!

Goldhshlager was able to pull this off by manipulating the OAuth URL, which allowed him to redirect a user to a test application he had set up. The test application would further redirect the oblivious user to Goldhshlager’s own site, where an access token would be stored.

A user usually needs to click on the ‘Allow’ button in order to let his information to be accessed. But Goldshlager was able to bypass this security process by going through Facebook’s messaging app. The message feature does not need a user to grant it any permission to access data, thereby cutting out the user completely from the process. The flaw continued to work till the user had changed his or her password, Goldhshlager noted.

Thankfully, the Goldhshlager brought this flaw to Facebook’s notice, thereby earning himself a place in the company’s White Hat Program hall of fame. “We applaud the security researcher who brought this issue to our attention and for responsibly reporting the bug to our White Hat Program,” a Facebook representative told Daily Dot. “We worked with Mr Goldshlager to make sure we understood the full scope of the vulnerability, which allowed us to fix it without any evidence that this bug was exploited in the wild, Due to the responsible reporting of this issue to Facebook, we have no evidence that users were impacted by this bug. We have provided a bounty to the researcher to thank them for their contribution to Facebook Security.”

Earlier this month, Facebook fell victim to a series of sophisticated attacks that had resulted in malicious software being installed on certain employees’ laptops. The incident occurred when a handful of employees visited a mobile developer website that had been compromised.

The discovery was made by Facebook security in January but the social networking site was quick to point out that they had found “no evidence that Facebook user data was compromised.”

STORY CONTINUES BELOW THIS AD
Tags
facebook Social Networking white hat Facebook Security Facebook Malware Facebook Hacked Facebook compromised zero day Java exploits Nir Goldshlager OAuth OAuth permission
End of Article
Written by Nishtha Kanal
Email

Intrigued by all things social, Nishtha will invariably tweet about you. When not tweeting or writing about the next viral video, you will hear her proclaiming her love to Metallica, James Hetfield, Opeth, Akerfeldt and all bands that go 'growl'. She also obsesses about ACP Pradyuman and South Park and you will always find her moving around with a book. Her focus is on all the happening stuff in the tech domain, and she won't hesitate to take a shot at some of the oddball devices that make their way to our labs. see more

Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV