top | item 5269333

Hacker says security flaw let him access any Facebook profile

26 points| shirkey | 13 years ago |news.cnet.com | reply

5 comments

order
[+] judofyr|13 years ago|reply
Facebook's OAuth2 implementation is so broken. Homakov found a X-XSS-Protection-related issue: http://homakov.blogspot.no/2013/02/hacking-facebook-with-oau....

After reading Homakov's and Nir's discussions I started looking for some bugs myself. And guess what? ~10 hours later I found another access_token-stealing exploit that has the same implications as Nir's exploit (although mine doesn't work in all browsers). Reported it 2 days ago.

Wouldn't surprise me if there's more bugs/exploits to be discovered :(

[+] itsnotvalid|13 years ago|reply
And since Homakov gave quite a detailed description of the class of bugs, it would be quite dangerous to use a browser with an active session to facebook now.