Re: [Full-disclosure] Another minor facebook security flaw



On 20/09/2011 06:04, James Fife wrote:
I noticed a recent flaw in Facebooks security resolution process recently. After being asked to confirm my identity simply because I was using a different computer, I apparently took too long to
identify my friends in their photos. However, I was able to try two more times before being locked out. In which case Facebook provided the exact same photos with the same selection of people to name
in order to confirm my identity. What this means is that I could conceivably attempt to logon to a victims Facebook account from an unauthorized device to get such a prompt, and then take my time to
research the answers.

I dont have the link but there is a really neat image search engine. You point it at an
image (file->save image as?) and it will hunt down the URLs referencing similar images.

Have seen it used to find sites using "stolen" images - not sure if it would work
with fb image archives but worth a try.

Could prolly automate the whole thing with 20 lines of perl :-)

Jacqui

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: Slghtly Off topic
    ... I will upload small versions of my photos there, and friends will sometimes pass them along to others. ... Facebook doesn't have viruses or spam, but you should try to avoid signing up for their applications. ... I use it to keep in touch with extended family and farflung friends, and I will post photos of family events for others to enjoy. ...
    (rec.photo.digital)
  • Re: Where is everybody??!
    ... "friends" which leads back to my. ... I have a "smart phone", but it doesn't do much good when is has a stupid ... I would have as much of a relationship using Facebook as I have the 15+ ... You can post photos, videos and music, as well as share links. ...
    (rec.pets.cats.anecdotes)
  • Re: Where is everybody??!
    ... reply, but they do that on Facebook too) - I post something, hit "refresh", ... "friends" which leads back to my. ... I have a "smart phone", but it doesn't do much good when is has a stupid ... You can post photos, videos and music, as well as share links. ...
    (rec.pets.cats.anecdotes)
  • Re: Where is everybody??!
    ... "friends" which leads back to my. ... I have a "smart phone", but it doesn't do much good when is has a stupid ... I would have as much of a relationship using Facebook as I have the 15+ ... You can post photos, videos and music, as well as share links. ...
    (rec.pets.cats.anecdotes)
  • Mothers protest at Facebook ban on offensive breastfeeding photos
    ... Mothers protest at Facebook ban on 'offensive' breastfeeding photos ... Protesters outside Facebook's headquarters in Palo Alto, ...
    (uk.legal)