Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

July 6th, 2010, 16:47 GMT · By

Facebook Senior Engineer Hacked by his Colleagues

SHARE:

Adjust text size:


Facebook senior engineer hacked via evil twin attack
Enlarge picture
Several Facebook employees successfully hacked the password of a senior engineer as part of a challenge to test the security of the site's administrative system. In order to do it they employed an evil twin wireless attack.

Last month Twitter settled with the Federal Trade Commission following an investigation into two security breaches that resulted in unauthorized individuals obtaining access to the site's administrative system. Both incidents occurred in early 2009 and involved the compromise of accounts belonging to Twitter employees.

The first incident was the result of a classic brute force dictionary attack against a weak password (happiness), while the second was based on social engineering and involved the hacker compromising a personal email account first. As a result, the micro-blogging site was barred by the FTC for the next twenty years from misleading consumers about the extent to which it protects the security, privacy, and confidentiality of nonpublic consumer information. It was also forced to implement a comprehensive security program, that will be subject to independent audits for the next ten years.

According to TechCrunch, a Facebook site reliability engineer named Pedram Keyani was inspired by Twitter incidents and challenged his colleagues to try and hack him in a similar manner, the end game being access to the site's administrative system. The "hackers" didn't bother with phishing attacks or trying to infect the engineer's computer with password stealing malware.

Instead they went straight to the place where he was most vulnerable, at home. There the "hackers" instrumented what is known as an evil twin attack. They installed a rogue access point, duplicated the settings of his wireless network - same SSID, same channel - and waited.

Being in the comfort of his home and with his guard down, Keyani logged into the rogue access point without realizing anything was wrong. Unfortunately, his colleagues had a traffic snooper installed on the AP, which captured everything, including his Facebook password in plain text.

Keyani considers the test a success, which proves the strong security model of the site. "While they were able to access my personal Facebook account, they were not able to use this information to access any other account on Facebook," he told TechCrunch.

You can follow the editor on Twitter @lconstantin

TELL US WHAT YOU THINK:

1,661 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Infamous Twitter Hacker Gets Off Easy

Traffic Snooping Exercise at Security Conference Ends Ugly

High Profile Twitter Hacker Arrested in France

Hacker Steals and Leaks Twitter Confidential Corporate Documents

Twitter Admin Account Hacked via Social Engineering

READER COMMENTS:


Comment #1 by: Lord_Jereth on 06 Jul 2010, 19:29 UTC reply to this comment

"While they were able to access my personal Facebook account, they were not able to use this information to access any other account on Facebook,"

Well of course not. That's not what they were tasked with doing. They were specifically tasked with hacking YOUR account. Once that was accomplished they stopped. Are you really going to attempt to convince us that if a malicious hacker had access to the site reliability engineer's account that they couldn't farm it for further administrative access?

Way to whitewash it with bull, Bub.

Truth is, Facebook, as well as most other social networking sites, are one of the leading vectors for malware at the moment. After April's across-the-board relaxation of privacy policies, you can't convince us that our security is your number one priority, either.

Nice try,

LJ

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM