website statistics

Major Security Flaw Found In Facebook’s Mobile Site

A security enthusiast recently discovered that simply by searching a person through his phone number, anyone can view the entire profile of targeted the user on Facebook's mobile site.

When do you use Facebook?

View Results

Loading ... Loading ...
1 Star2 Stars3 Stars4 Stars5 Stars (Rate This)
Loading ... Loading ...

Facebook has been ramping up the security of the social network to ensure the privacy as well as security of user data. However, it seems that the security measures were focused more on the regular website, with the mobile website being ignored on the way. A security researcher has now discovered a major flaw in the latter; one which could compromise the data of millions of users.

Suriya Prakash is a security enthusiast and he is the one who discovered the vulnerability in Facebook’s mobile site. Prakash said that he alerted Facebook about the flaw but the social network giant didn’t attend to his discovery.

According to him, “About a month ago I was just browsing Facebook on my Facebook mobile application and it had an option called ‘Find friends using contacts’ — what it does is that it compares the contact list from your phone to the Facebook database to see if you have any friends that are in your contacts but not on your Facebook account.”

Prakash further says that he realized that by simply searching any person’s phone number, he could view that person’s account. He then wrote a script which automatically populated his phone book and then used this phone book to view the accounts of thousands of people. The script kept running for four days straight without any qualms and only then did Facebook realize the activity that was going on.

Facebook, on the other hand, released a statement saying, “Facebook has developed an extensive system for preventing the malicious usage of our search functionality and the scenario described by the researcher was indeed rate-limited and eventually blocked. We are constantly updating these systems to improve their effectiveness and address new kinds of attacks.”

Courtesy: Hot Hardware

Buy Cheapest Related Product From Amazon.com


WikiLeaks Launches ‘PayWall’ For Accessing Leaked Material, Angers Supporters

HP Turns Down Gartner Report, Claims To Be The Top Global PC Maker
You can also press the left/right arrow key on your keyboard to go to previous/next post
  On October 13, 2012(7 months, 13 days ago.)

Recent Products

Buy Now | Compare  
Buy Now | Compare  
Compare  

Recent Search

Recent Tutorials

This tutorial will show how to use S.M.A.R.T. (Self Monitoring Analysis and Reporting Technology) to continuously collect information on health of your equipment.
In this tutorial I'll show you how you can easily protect yourself from any kind of security breaks that may occur through Java.
Today Apple enabled "Two Step Verification" for iCloud And Apple ID. But the process is not that simple. But no worry, here we have made a step by step tutorial.
Cant remember your iPhone passcode? Here I will show you some workaround on what to do and how to recover and restore for every possible scenario.
This tutorial will show you how to perform the Winapp2.ini installation inside CCleaner and how to use it under Windows operating system.
With app called AD Sound Recorder, you can record any stream that passes through your sound card or speakers and in this tutorial I will show you how to do that.
If you want to have Boxee app inside your Apple TV, in this tutorial we will show you how to install XBMC and Boxee using Windows on your Apple TV.
This tutorial will show you how to transfer PS3 Saved Game Files from your PC to your PS3 game console.
Adding videos from external sources such as internet, more specifically from YouTube, is a great solution to enhance a presentation; in this tutorial I will show you the procedure.
If you are one of new comers to Windows Phone 8, like me, in this tutorial I will walk you through the process to update your Windows Phone 8 device.
Close You Have To Login
User:
Pass:
Login With »Login With TwitterLogin With Facebook