Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

September 26th, 2012, 08:01 GMT · By

BLOG

Researcher Finds Open Redirect Vulnerability in Facebook [Video]

SHARE:

Adjust text size:


Security researcher Rafay Baloch claims to have found an open redirect vulnerability in Facebook. To demonstrate his findings, he published a proof-of-concept video on his blog.

Open redirect can be used by cybercriminals to trick victims into thinking that they’re about to visit a safe website, when in fact they’re being directed to an arbitrary domain.

In order to protect its users against attacks that rely on open redirect, Facebook has implemented a system that warns customers in case they are about to visit a potentially malicious website.

However, the expert identified a way to bypass – at least partly - this protection mechanism. The vulnerability he has discovered is caused by a parameter filtering weakness and it can’t be used as a completely open redirect, but it can be utilized to a certain extent.

The social media network’s representatives acknowledged the existence of the flaw, but it’s uncertain if they will address the issue.

“This endpoint contains a specialized parameter that limits its */usage to a small number of computers and users/*, preventing it from being used as a completely open redirect. For more detailed background information, please see this note by one of the engineers on the product,” they explained.

TELL US WHAT YOU THINK:

1,497 hits · 3 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Stonesoft to Host First Cyber Security Summit on October 24, 2012

Backdoor in phpMyAdmin Allows Hackers to Execute PHP Code

Expert: USSD Codes Can Be Used to Remotely Reset Samsung Galaxy S3 Phones

One Billion Users Affected by Java Security Sandbox Bypass Vulnerability, Experts Say

Rapid 7 Releases ScanNow, MySQL Authentication Bypass Flaw Scanner

READER COMMENTS:


Comment #1 by: Rafay Baloch on 26 Sep 2012, 10:41 UTC reply to this comment

Thankyou very much for sharing the word.


Comment #2 by: dr musrat on 21 Oct 2012, 20:01 UTC reply to this comment

face should take this flaw seriously and should be thankful to rafay baloch


Comment #3 by: dr musrat on 21 Oct 2012, 20:01 UTC reply to this comment

face should take this flaw seriously and should be thankful to rafay baloch

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM