TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Hacker says security flaw let him access any Facebook profile

26 pointsby shirkeyabout 12 years ago

2 comments

judofyrabout 12 years ago
Facebook's OAuth2 implementation is so broken. Homakov found a X-XSS-Protection-related issue: <a href="http://homakov.blogspot.no/2013/02/hacking-facebook-with-oauth2-and-chrome.html" rel="nofollow">http://homakov.blogspot.no/2013/02/hacking-facebook-with-oau...</a>.<p>After reading Homakov's and Nir's discussions I started looking for some bugs myself. And guess what? ~10 hours later I found <i>another</i> access_token-stealing exploit that has the same implications as Nir's exploit (although mine doesn't work in all browsers). Reported it 2 days ago.<p>Wouldn't surprise me if there's more bugs/exploits to be discovered :(
评论 #5270849 未加载
评论 #5269653 未加载
sktrdieabout 12 years ago
No proof of the exploit?
评论 #5269470 未加载
评论 #5269514 未加载