HomeSecurityFacebook: Clickjacking bug that will not be fixed

Facebook: Clickjacking bug that won't be fixed

A security researcher accidentally discovered a method by which hackers run campaigns on Facebook's platform, and reported it to the company's bug bounty program. Facebook ignored the researcher's report, and has not taken any action to limit it, as the specific method does not change the status of users' accounts in any way.

 

The POC (proof of concept) code has been published showing how easy it is for a developer to share a link multiple times.

The security researcher began analyzing the campaign when he noticed that many of his Facebook friends were sharing a particular link with funny images. When he opened that link, before he could even see the funny images, he was asked to confirm that he was over 16 years old.

"After someone confirms that they are over 16 years old, you are taken to the page with the funny images. What they don't know, however, is that they automatically share the link from their account.".

Facebook

What he discovered with a quick look at the page's code is a suspicious iframe tag, which contains a URL responsible for the automatic sharing. This particular method targets Facebook mobile users and only works if the selected language is French.

This particular method is called click jacking. It works by loading an iframe that is in a hidden layer in front of the page we want to view.

Facebook quickly responded to the report, and stated that it would not make any changes, as this method does not alter the user's account in any way, so there is no security issue.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS