Security firm Imperva discovered a bug in May that allowed websites to access Facebook users' data and the personal information of their friends.
The bug allowed websites to access users' preferences and interests through a query in Facebook's Graph search. Fortunately, the problem has already been fixed by the largest social network.
Imperva researcher Ron Masas discovered in May that Facebook was allowing cross-site request forgery (CSRF) attacks. This means that another website could access Facebook user data through queries in the code.
To exploit the bug, a website would have to use an iframe that displayed Facebook within its pages.
So if a user logged into Facebook visited the page with the malicious code, the script would start collecting data by sending queries to the social network via Graph search: “Does the user have friends?” or “Does he have friends in Canada?”
You can see an example in the video below.
Imperva researcher Ron Masas also reported that the attack also allowed access to users' friends' data, even if the information was only visible to friends.
A Facebook spokesperson told TechCrunch that no data was lost. Imperva, a company that has been in the news for two separate bugs, won $8,000 for reporting them to Facebook.
The story comes to remind us that there is no security on the internet. The moment your data is stored on the internet, it ceases to be yours and becomes shared with the first hacker who manages to break the system.
_______________
- VisBug from Google, a new practical dev tool
- Facebook introduces the Lasso app
- DTP Facebook Google Microsoft Twitter: data portability project
- Have you tried using the Facebook app lately?
- Facebook sued for post-traumatic stress disorder
