You're Not Safe Using Facebook Apps
Researchers Test Facebot
In the name of finding any possible way that hackers can get at your data, a group of researchers has penetrated Facebook via a could-be-malicious application proving that Facebook Apps are unsafe. The app seems harmless enough. It's a National Geographic "photo of the day" app that gives users (obviously) a different photo each day.

What users of this app don't see, however, is that there are some evil (if in the wrong hands) things going on behind the scenes. The research paper gets a little complicated, but PC World sums it up nicely:
In the background, every time the application is clicked, it sends a 600 K-byte HTTP request for images to a victim's Web site.
Those requests, as well as those images, are not seen by someone using Photo of the Day, which the researchers have termed a "Facebot" application. The effect is a flood of traffic to the victim's Web site, known as a denial-of-service attack.
According to the researchers, a "facebot" application could grab personal details from a user's Facebook account and post them to a remote server. This should make application users feel a little uneasy, particularly those who like their privacy.
Ryan Singel at Wired says, "Now, coders who control a really popular social networking app aren't likely to jeopardize their oil well for a prank, but it would not be hard for a slightly popular application to become rogue without anyone ever knowing or being able to figure out it was happening."
The research paper points out that Facebook could prevent such applications from appearing on the social network. They would have to make sure that the apps didn't interact with outside hosts.
Social network security is probably going to be an increasingly important topic as social media continues to gain popularity, and see widespread use among more platforms. Social networks are being integrated more with mobile devices, blogs, and business web sites, and this is where trouble could really start to snowball.
The internet sure is a funny place isn’t it?
-

Real-Time Search Engines Rush to Fill New Need
Twitter has produced a hot new trend: real-time search. -

Google's OS to Challenge Microsoft?
Googlers Sundar Pichai and Linus Upson announced on Wednesday that... -

Is Twitter Scaring Google?
There have been multiple reports that Twitter could replace Google. -

User Authentication Services: Good or Bad?
Products such as OpenID, Facebook Connect, and Google Friend Connect...
High-Tech Drugs May Get 12-Year... TheStreet.com:...
Is the outlook on the economy... BloggingStocks
Snake oil at its slickest: A... ZDNet Blogs
Best Practices For Auditing An SEM Search Engine Land
iEntry 10th Anniversary
RSS
Newsletter
Advertising




















4 Comments
So what is the big
So what is the big news?
That anything can be hacked somehow sometime on the internet?
Interesting
Hmm... I would think that there are far easier ways of doing a DOS attach than building a facebook app. I am wondering what the financial advantage of such a thing would be.
Media Campaign for Equity
I'm interested in reaching social network websites who are interested in trading equity for a $10,000,000 media campaign.
I read this paper and added
I read this paper and added the app (http://www.new.facebook.com/apps/application.php?id=8752912084)
It sounds cool that Facebook can become an attack platform.
I am wondering if Facebook has security holes, like this described in the paper .....
Post new comment