|
|
Facebook Vulnerable To ClickjackingFacebook contains vulnerabilities that would permit an attacker to hijack an account while a user is browsing another Web site, says a security researcher. Researcher Nitesh Dhanjani also says a flaw in Facebook's template is giving third-party apps permission to view user profile information without users' express consent. The company has changed its warning policy so that some new apps include an implicit authorization feature that does not caution Facebook users that a third-party app is attempting to access their information, Dhanjani says. "This allows Facebook to gain increased adoption of third-party apps, which can translate to revenue," he says, noting that a warning would scare some users away from new apps. In a separate study that closely correlates with the new findings, Dhanjani and Israeli security analyst Shlomi Narkolayev say hackers could wield "clickjacking" attacks to penetrate Facebook accounts by duping users into visiting sites embedded with malware code. A Web site that appears to be an e-commerce page showing videos could obscure a Facebook log-in page behind it so that when a user accesses the site to see a video, for example, his or her account is opened instead in the background, without the user's knowledge. "Using ClickJacking I also could fool users to click whatever I want: Adding me as their friend, delete their account, and even open their camera and microphone using flash (Older versions then 10.x), or install Facebook applications that post their Web camera and microphone every time they connected to Facebook," Narkolayev writes on his blog. What is clickjacking? Clickjacking is a malicious technique of tricking Web users into revealing confidential information or taking control of their computer while clicking on seemingly innocuous Web pages. A clickjacking takes the form of embedded code or script that can execute without the user's knowledge, such as clicking on a button that appears to perform another function. |
2010 Pre-employment Screeners in Human Resources Conference - Clearwater Registration Conferences Photos and Presentations Testimonials of our Conferences
|