На информационном ресурсе применяются рекомендательные технологии (информационные технологии предоставления информации на основе сбора, систематизации и анализа сведений, относящихся к предпочтениям пользователей сети "Интернет", находящихся на территории Российской Федерации)

Feedbox

12 подписчиков

Facebook bug allowed websites to grab unsuspecting users’ personal data

Author: Ivan Mehta / Source: The Next Web

Facebook bug allowed websites to grab unsuspecting users’ personal data

Security firm Imperva found a bug in May that allowed websites to read Facebook users and their friends’ private information. The troubling vulnerability let a site access users’ likes and interests through a manipulated Facebook Graph query. Thankfully, the bug has now been fixed

Imperva’s researcher Ron Masas discovered in May that Facebook was exposed to cross-site request forgery (CSRF).

That means another website can access a logged-in Facebook user’s data through queries in code.

To exploit the bug, a site can embed an IFRAME – a site within a site – to siphon off data from a user. When a logged-in Facebook user visits a website with malicious code and clicks anywhere, the script will begin to gather data by sending queries to the social network, like “Does…

Click here to read more

The post Facebook bug allowed websites to grab unsuspecting users’ personal data appeared first on FeedBox.

Ссылка на первоисточник
наверх