Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

January 7th, 2013, 16:00 GMT · By

BLOG

Password Reset Flaw Found in Facebook's Employee Secure File Transfer Service – Video

SHARE:

Adjust text size:


Security researcher Nir Goldshlager has identified a flaw in the Secure File Transfer service used by Facebook employees, which allowed him to reset the password of any account.

Accellion, the provider of the file transfer service, had removed the registration page to prevent unauthorized users from creating accounts. However, Goldshlager discovered that the registration page could still be accessed by someone who knew its location.

After creating an account and downloading the Accellion application, he attempted to reverse engineer the source code files, but since they were properly encrypted, he pursued a different attack vector.

He identified a “referer” parameter in the cookie used by a file called wmPassupdate.html – utilized by the application to recover forgotten passwords.

By changing the values of this parameter, he could set the password of any account to an arbitrary one.

After being notified by the expert, both Facebook and Accellion addressed the security holes. To see the details of the vulnerability, check out the video proof-of-concept published by Goldshlager.

TELL US WHAT YOU THINK:

1,533 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Flaw in Facebook Allowed Attackers to Record Video of User and Post It on the Timeline – Video

Skype 0-Day Vulnerability Allowed Hackers to Change the Password of Any Account – Video

Zero-Day Vulnerability Uncovered in Symantec’s PGP Whole Disk Encryption

AOL Shopping Website Plagued by XSS and iFrame Injection Vulnerabilities

SQL Injection, XSS Vulnerabilities Found on the Site of Islami Bank Bangladesh

READER COMMENTS:


Comment #1 by: internal on 09 Jan 2013, 05:31 UTC reply to this comment

This was a very old issue, found and fixed on the next day in March 2012. Why bring it now?

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM