Providing Free and Editor Tested Downloads

< HOME | MAC | GEEK - WEAR | SHOPPING | SUPPORT FORUM | TOP DOWNLOADS | >
MajorGeeks.com - Helping you void your warranty since 2002.

Admin Tools
All In One
Android
Anti-Spyware
Anti-Virus
Appearance
Back Up
Benchmarking
Bios
Browsers
CD\DVD\Blu-Ray
Covert Ops
Data Recovery
Diagnostics
Drive Cleaners
Drive Utilities
Driver Tools
Drivers
Ergonomics
Firewalls
Game Tweaks
Graphics
Input Device
Internet Tools
Mail Utilities
Memory
Messaging
Microsoft
Misc
Monitoring
Multimedia
Networking
Office Tools
ProcessManagement
Processor
Registry
Security
System Info
Toys
Video
Macintosh
Games
News Archive
- Off Base
- Way Off Base


· Hmonitor 4.5.3.3
· WinHTTrack 3.47-13
· WinSCP 5.1.5
· 4k Video Downloader 2.7.1
· Xeoma 13.4.30
· Free USB Guard 1.41
· Hippo Animator 2.6.4885
· HandBrake 0.9.9
· J. River Media Center 18.0.188
· Gmail Notifier Pro 7.3

There are currently 3010 user(s) online:
Google, Live Search, MSN, Yahoo

YouTube

FaceBook

Twitter

RSS / XML Feed

Pintrest



Follow @majorgeeks
· Google · Yahoo · MSN


1. K-Lite Codec Pack Update
2. IObit SmartDefrag
3. Malwarebytes Anti-Malware
4. Win7codecs
5. IObit Malware Fighter
6. Windows 8 Codecs
7. SpywareBlaster
8. x64 Components
9. JetClean
10. Start Menu 8
More >>


· New? Start Here
· Top Freeware Picks
· Malware Removal
· Compatibility Database
· Geektionary
· Geek Shopping
· Free Magazines
· Useful Links
· Top Freeware Picks
· Folding@Home
· About Us
· Copyright
· Privacy
· Terms Of Service
· Uninstall


MajorGeeks.com » News » August 2012 » Security hole in Facebook nets researcher $5000

Security hole in Facebook nets researcher $5000


Posted on: 08/23/2012 05:05 PM [ Comments ]


A security researcher who goes by the name of AMol NAik has disclosed a security hole in Facebook's web site. The cross-site request forgery (CSRF) flaw allows an attacker to execute actions as a logged-in user by accessing specific URLs. The researcher earned a bounty of $5,000 for responsible disclosure of the vulnerability before publishing it.

After Facebook introduced its App Center functionality, AMol NAik discovered that the anti-CSRF tokens in HTTP requests are apparently not validated on the server side and that an attacker is therefore able to add applications on the platform as another user. To execute this attack, the attacker merely needs the victim to visit a specially crafted web site, after which malicious applications can be planted on the App Center.

Anti-CSRF measures like the ones employed by Facebook are supposed to prevent this kind of attack by generating a token with every valid session that has to be sent by the client with every request. Scripts on other web sites have no access to this token and therefore cannot generate valid requests. In Facebook's case, the App Center pages did not actually check the token for validity, which allowed anyone to send bogus requests and have them accepted. The Facebook Security team fixed the vulnerability within one day of being contacted by AMol NAik.








Like it? Share it....




Comments
comments powered by Disqus

« LulzSec hacker gets six months of freedom in exchange for cooperation · Security hole in Facebook nets researcher $5000 · Florida Friday: He was naked, on crack and in alligator's mouth »

MajorGeeks.com » News » August 2012 » Security hole in Facebook nets researcher $5000
© 2000-2013 MajorGeeks.com
Powered by Contentteller® Business Edition