Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

January 8th, 2013, 09:53 GMT · By

BLOG

Facebook Fixes Flaw That Allowed Hackers to Change Password Without Knowing the Old One

SHARE:

Adjust text size:


Facebook password reset vulnerability - step 1 Enlarge picture - Facebook password reset vulnerability - step 1
Facebook has addressed a serious vulnerability after being notified by independent security researcher Sow Ching Shiong. The security hole allowed hackers to change the passwords of accounts they had compromised without knowing the old passwords.

Whenever users change the password that protects their Facebook account, they’re required to enter the current password before they can set the new one.

However, the expert found that cybercriminals could change a user’s password without knowing the old one by accessing the “https://www.facebook.com/hacked” URL, which automatically redirected to the compromised account recovery page.

By using this method, an attacker was simply prompted to enter the new password and confirm it, without having to know any other information.

Facebook has addressed this issue and now users are prompted to enter their old passwords before setting a new one.

Sow Ching Shiong has been added to Facebook's list of white hats. 

Check out the screenshots from the gallery to see how the attack worked.

FACEBOOK PASSWORD RESET VULNERABILITY - PHOTO GALLERY:

TELL US WHAT YOU THINK:

2,432 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Password Reset Flaw Found in Facebook's Employee Secure File Transfer Service – Video

AOL Shopping Website Plagued by XSS and iFrame Injection Vulnerabilities

SQL Injection, XSS Vulnerabilities Found on the Site of Islami Bank Bangladesh

XSS Vulnerability in HostGator India Affects over One Million Websites

Zero-Day Vulnerability Uncovered in Symantec’s PGP Whole Disk Encryption

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM