PoC for Facebook Worm: A Polish security researcher today published a PoC that could be used to create a fully functional Facebook worm.
The code exploits a security flaw in Facebook's platform. The researcher, who goes by the pseudonym Lasq, discovered the vulnerability when he noticed it being used by spammers on Facebook.
The vulnerability is in the mobile version of the app. The desktop version is not affected.
Lasq reports that the vulnerability allows clickjacking and that an attacker can exploit it via iframe elements.
Yesterday I noticed a very annoying SPAM campaign on Facebook, where many of my friends were posting a link to a site hosted on an AWS bucket. There was also a link to a French site with funny comics.
After clicking the link, the page hosted on the AWS bucket appeared, asking you to verify that you were 16 years old or older (in French) to access the content. After clicking the button, the page redirected you to a page with funny comics (and lots of ads). However, in the meantime, the same link you just clicked also automatically posted to your Facebook wall.
The researcher followed the issue and noticed that it was completely ignoring the security header “X-Frame-Options.” This header is used by websites to prevent page code from loading inside iframes and is a primary protection against clickjacking attacks.
Lasq said he reported the issue to Facebook, but the company refused to fix it. So he decided to publish the PoC.
Lasq's code doesn't include the clickjacking part, the part that posts content to victims' walls, but if you're interested and want to find it, it's available online with a simple search. Lasq's code only allows an attacker to upload and execute unauthorized code on a Facebook user account.
_____________
- Old Facebook messages are randomly returning to users
- LibreOffice 6.1.4 new release from the Document Foundation
- Facebook Investigation by DPC into leaked photos
- Facebook two-factor authentication without a phone number
