Skip to main content

Nir Goldshlager: How I Hacked Facebook To Get Full Permissions On Any Facebook Account

posted onFebruary 22, 2013
by l33tdawg

Israeli security researcher, Nir Goldshlager has found a way to abuse Facebook's OAuth mechanism allowing for complete account take over. From his blog:

I decided to share one of my favorite flaws i discovered in  facebook.com,
This flaw allowed me to take a full control over any Facebook account,
 
By exploiting this flaw I could steal unique access tokens that provides me full control over any Facebook account,
  
just to clarify there is no need for any installed apps on the victim's account, Even if the victim never allowed any application in his  Facebook account, I could still be getting full permissions (This bug works on any browser)

To make this exploit work, The victim only need to visit a webpage,
So OAuth is used by Facebook to communicate between Applications and Facebook users, Usally users must allow/accept the application request to access their account before the communication can start.

Any Facebook application might ask for different permissions.

Source

Tags

Facebook Security Privacy

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th