Jump to content
akkiliON

Vulnerability allows Hacking Facebook account and password reset within a minute

Recommended Posts

  • Active Members
Posted

Security expert Dan Melamed discovered a critical vulnerability in Facebook platform that allow an attacker to take complete control over any account.

q3xu.jpg

The vulnerability is considered critical because it would allow a hacker to hack potentially any Facebook account. Dan Melamed presented the discovery on his blog.

Dan demonstrated that how a hacker can reset the victim's account password just by tricking him to visit a malicious exploit code.

The flaw affects the Facebook "claim email address" component. When an user tries to add an email address already registered to Facebook platform, he has the option to "claim it"". The loophole exists here, when user claim an email address, Facebook did not check from whom the request came from. This allows an email to be claimed on any Facebook account.

The exploit is possible provided that:

  • An existing account having the email address that the attacker wants to claim.
  • Another existing account to initiate the claim process.

Dan provided a video of proof of concept:

When user makes a claim request for an @hotmail.com email he is taken to a link that appears like this:

https://www.facebook.com/support/openid/proxy_hotmail.php?appdata[fbid]=AQ3Tcly2XEfbzuCqyhZXfb8_hYHTnHPPd-CDsvdrLzDnWLpsKTMcaXtIzV0qywEwbPs

The researcher discovered that the parameter appdata[fbid] was the encrypted email address. Dan used the encrypted email funnyluv196@hotmail.com for the POC. The link will redirect user to the sign in page for Hotmail.

You must sign in with the email address that matches the encrypted parameter. Once signed in, you are taken to a final link that looks like this:

https://www.facebook.com/support/openid/accept_hotmail.php?appdata=%7B%22fbid%22%3A%22AQ3T cly2XEfbzuCqyhZXfb8_hYHTnHPPd-CDsvdrLzDnWLpsKTMcaXtIzV0qywEwbPs%22%7D&code=a6893043-cf19-942b-c686-1aadb8b21026

The source code confirms that the claim email process has succeeded:

s3p9.png

Dan Melamed sustains that the exploit is very simple to conduct and it is advantaged by 2 important aspects:

  • The link expires in around 3 hours, giving plenty of time for a hacker to use it.
  • It can be visited on any Facebook account because there is no check to see who made this request.

To trick the victim, hacker has just to insert the (http://evilsite.com/evilpage.html) exploit link on a webpage as either an image or an iframe.

ih89.png

Once clicked, the email (in this case: funnyluv196@hotmail.com) is instantly added to their Facebook account. The victim does not receive any notification whatsoever that this email has been added. The hacker can then reset the victim's password using the newly added email address. Thus allowing the attacker to take complete control over the Facebook account.

This vulnerability has been confirmed to be patched by the Facebook Security Team, fortunately the group is very responsive as demonstrated for the fix of other recent flaw. It must be considered that the popular social networking platform is very attractive for cybercrime and many other categories of attackers, cyber security is a critical aspect for its business success.

Vulnerability allows Hacking Facebook account and password reset within a minute -TheHackerNews

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...