|
|
|
You are here: News > News > Facebook rushed to fix the newly-founded glitch
| » IT Security NEWS |
| » 20 May 2010 |
| Facebook rushed to fix the newly-founded glitch |
According to a security expert, the administrators of the famous social networking site are currently polishing the remedy for the sensitive security threat that was found on Facebook. This privacy glitch allows unauthorized viewing of birthdays and other private information that were originally set as private.
Abuse of security bug is part of an endless cycle
M.J. Keith, the senior security analyst, and the cloud-based intrusion detection system provider Alert Logic both believed that there is a big possibility that this security vulnerability may be abused by online thugs. This can be done by having a user access a certain link while he or she is still logged into Facebook.
When online criminals find their way around the security system, they will be able to gain access into the profile page of a user. The individual will then become a victim of the attack when the web crook ends up reading, deleting, or even modifying the data written on the profile page. The photos and data might also be affected even if the page is set to be viewed only by the users on the list of contacts.
This glitch is found to be very powerful since the online thugs have the same amount of control as with the Facebook users. Thus, each of the individuals is at risk of having their profile page ruined and all their confidential data exposed to the public.
Even small problems still persist
At present, the cross-site request forgery glitch has already been patched up. But then, there is still a minor abuse that can occur because of the presence of this vulnerability. The “like” function of Facebook might be utilized by the online crooks so as to give support to different kinds of ads and contents.
The vulnerability originated from a single code that is called the “post_form_id” by the Facebook staff. This code is utilized in a way that it guarantees that the commands are delivered by the web browsers, which was used to access the site.
Security vulnerabilities appear more frequently
Based on the previous reports, it can be noted that this vulnerability is the second security flaw recorded this month. Just about nine days ago, the live chat function was deactivated by Facebook because of a certain bug that permits users to view the conversation of their friend with another person.
As of the moment, the administrators of Facebook have not released any statement regarding the condition of the said glitch.
Read more information through the given SecPoint Links: About SecPoint, SecPoint Products, and SecPoint Press. |