Showing posts with label Facebook. Show all posts
Showing posts with label Facebook. Show all posts

Wednesday, April 17, 2013

0

How Strangers Can Read Your Private Facebook Messages

  • Wednesday, April 17, 2013
  • Nauman Ashraf
  • If your private message is flagged by Facebook automated tools, then Facebook team/employees are going to your message and contact law enforcement if its regarding child exploitation.


    Facebook has a team of employees who read your private messages if they have been flagged by an automated tool. The tool searches for content that appears to violate their terms of service, namely malicious (infected) URLs or child pornography. It's imperfect, of course — that's where humans come in, According to BuzzFeed.

    If a private message is flagged, actual people will jump in and read it. If there is something that could be illegal — particularly regarding child exploitation — those people contact law enforcement. The intent here is clear and defensible, yet the fact remains: All that stands between your "private" messages and the eyes of a stranger is the snap judgment of an algorithm, BuzzFeed adds.

    It's not just Facebook. Dating site OkCupid has humans read private messages that have been flagged by its users.Twitter doesn't monitor direct messages either through automated tools or humans.
    Read More..

    Saturday, March 23, 2013

    0

    Facebook Hacker Cup 2013 Won By Petr Mitrichev

  • Saturday, March 23, 2013
  • Nauman Ashraf
  • Facebook Announced the Winners of the 2013 Facebook Hacker Cup. So The Winner of Facebook Hacker Cup 2013 is Petr Mitrichev. In second place, We have Jakub Pachocki and In third place, We have Marcin Smulewicz.Congratulations to the Winners!

    Below is the picture of Petr Mitrichev, holding winning check for $10,000 dollars!


    Petr Mitrichev solved all of the four problems (Archiver, Colored Trees, Minesweeping, Teleports) in a due time.

    The Highly Coveted Hacker Cup Trophy:

    About Facebook Hacker Cup:
    The Facebook Hacker Cup is an annual worldwide programming competition where hackers compete against each other for fame, fortune, glory and a shot at the coveted Hacker Cup.
    According to FBHacking is core to how we build at Facebook. Whether we’re building a prototype for a major product like Timeline at a Hackathon, creating a smarter search algorithm, or tearing down walls at our new headquarters, we’re always hacking to find better ways to solve problems. In the Hacker Cup, programmers from around the world will be judged on accuracy and speed as they race to solve algorithmic problems to advance through up to five rounds of programming challenges. This is your chance to compete against the world’s best programmers for awesome prizes and the title of World Champion.
    Read More..

    Saturday, March 16, 2013

    0

    Pakistani Security Researcher gets 500$ Reward for Facebook Bug Bounty Program

  • Saturday, March 16, 2013
  • Nauman Ashraf
  • A Pakistani Security Researcher, Former Black Hat - Haider Mehmood Qureshi, gets 500$ reward from Facebook under Facebook Bug Bounty Program for reporting HTML Injection flaw on Facebook mobile site.

    Below are the details of Bug provide by the Researcher to The Hackers Post.

    [#] - Vulnerability Title:
                               HTML Injection

    [#] - Vendor homepage: 
                              http://m.facebook.com

    [#] - Remote/Local: 
                             Remote

    [#] - Tested on: 
                            Windows 7 64 bit Firefox browser  (but should have worked on other OS and browsers                      (not sure about IE))

    [#] - Vulnerability Submitted:  
                            12/1/2013

    [#] - Vulnerability Status: 
                             FIXED

    [#] - Vulnerable  Parameter: 
                            https://m.facebook.com/survey.php?incorrect_brand&params=

    Facebook mobile provides a survey to evaluate the mobile user experience as they surf facebook mobile site. Here is the survery  link: https://m.facebook.com/survey.php .

    While entering the mobile phone brands , it provides a list of brands in case you didn't type the correct brand.


    The list that was provided contained their HTML code inside the parameter

    https://m.facebook.com/survey.php?incorrect_brand&params=[HTML code of Brands and Radio Buttons]

    Remote User can add any brand Name and Radio buttons, hence allowing Remote HTML injection. It was as simple as it sounds. This could also result in adding junk entries into to database hence causing spam, because remote user can add entries and submit.

    Below is the screenshot of a  portion of exact POC Researcher submitted to Facebook:



    Below my the first reply from Facebook and they acknowledged the issue



    below is their reply after 2 months when they fixed the issue



    below is their email regarding my eligibility of bug bounty and details.



    There is increase rise in black hats changing their dimensions towards bug reporting rather than exploiting them. Yesterday, we reported the youngest security researcher found XSS flaw on Amazon Site.

    About Security Researcher Haider:
    Haider Mehmood Qureshi is a BS Computer Sciences Student from Comsats Intitute of information technology Islamabad, He do freelancing as Penetration Tester, Started learning pentesting/hacking in 2009. Initially, he was into defacing websites just for fun, later realized to make Pentesting/Security auditing as my career. You can contact security researcher here.
    Read More..

    Saturday, February 16, 2013

    1

    Facebook hacked by Java Zero Day exploit

  • Saturday, February 16, 2013
  • Nauman Ashraf
  • Facebook - a social networking giant with one billion active users said on Friday that it has been attacked by an unidentified group of hackers in January, fortunately no user information was compromised during the attack.

    What is really interesting is the level of sophistication of the malware based attack that eluded security defense, it compromised the developer’s website and infected the employee's machine when visited it.

    The laptops infected were fully-patched and running up-to-date anti-virus software occurrence that suggests attacker have exploited zero day vulnerabilities hosting an exploit on the web site.

    The official statement reports:
    “Facebook, like every significant internet service, is frequently targeted by those who want to disrupt or access our data and infrastructure. As such, we invest heavily in preventing, detecting, and responding to threats that target our infrastructure, and we never stop working to protect the people who use our service. The vast majority of the time, we are successful in preventing harm before it happens, and our security team works to quickly and effectively investigate and stop abuse. 
    Last month, Facebook Security discovered that our systems had been targeted in a sophisticated attack. This attack occurred when a handful of employees visited a mobile developer website that was compromised. The compromised website hosted an exploit which then allowed malware to be installed on these employee laptops. The laptops were fully-patched and running up-to-date anti-virus software. As soon as we discovered the presence of the malware, we remediated all infected machines, informed law enforcement, and began a significant investigation that continues to this day.”
    Facebook confirmed no user data was compromised.
    We have found no evidence that Facebook user data was compromised.
    Facebook advisory confirmed that security teams of the company are very active in the fight to cyber threats thanks to an intense collaboration with law enforcement and security teams of other companies. The attacks seem to have exploited a zero-day Java software vulnerability well before the official announcement provided by Oracle company.

    “After analyzing the compromised website where the attack originated, we found it was using a “zero-day” (previously unseen) exploit to bypass the Java sandbox (built-in protections) to install the malware. We immediately reported the exploit to Oracle, and they confirmed our findings and provided a patch on February 1, 2013, that addresses this vulnerability.”

    The investigation are still ongoing as confirmed by Facebook
    “We will continue to work with law enforcement and the other organizations and entities affected by this attack. It is in everyone’s interests for our industry to work together to prevent attacks such as these in the future.”

    Facebook has a very managed bug bounty program which attracts Bug Bounty Hunter to participate in it and report vulnerabilities to facebook.
    Read More..

    Subscribe