The Enterprise Security Supersite
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Network Security Viruses & Malware Spam & Hackers Security Products More Topics...
Network Security
Average Rating:
Rate this article:  
Facebook Hijacking Points To Social-Networking Holes Facebook Hijacking Points To Social-Networking Holes
By Carl Weinschenk
November 10, 2009 2:19PM

Bookmark and Share
The nontechnical hijacking of nearly 300 unadministered Facebook groups illustrates the security issues facing social-networking sites. Dave Amsler of Foreground Security said social-networking sites like Facebook have major security issues. Facebook said the takeover of the groups was not a hijacking and no confidential information was exposed.
 


The takeover of administration rights to a large number of Facebook groups by an organization that calls itself Control Your Info is just one example of the many security issues facing social-networking Relevant Products/Services sites in general and Facebook in particular, according to experts.

Indeed, this nontechnical exploit can be called a benign example of what is at risk if better controls aren't put in place. Control Your Info hijacked almost 300 groups by simply taking over unadministered groups. Dave Amsler, the cofounder and CIO of Foreground Security, said the illegitimate administrators have access to profile information, e-mail addresses and other data Relevant Products/Services that members have provided. He pointed out that credit-card numbers aren't involved.

Hijacker Message

Control Your Info posted this message at those groups:

"Hello, we hereby announce that we have officially hijacked your Facebook group.

"This means we control a certain part of the information about you on Facebook. If we wanted we could make you appear in a bad way which could damage your image severly [sic]."

The group didn't respond to a request for an interview sent to the e-mail address at its web site.

Facebook's press-relations department e-mailed a statement which read in part that "there has been no hacking and there is no confidential information at risk. The groups in question have been abandoned by their previous owners, which means any group member has the option to make themselves an administrator in order to continue communication to the group. Group administrators have no access to private user information and group members can leave a group at any time."

Bigger Problems

The situation is evidence of significant vulnerabilities in Facebook, Amsler said. "The social-networking sites -- Facebook being the most important -- have major security issues," he added. "No one is bothering to secure anything."

He said the company seemed unconcerned when contacted. "We've reported major findings to them and their response is, 'Yeah, we know about it. There is not a whole lot we can do about it.'"

Amsler added that he agrees with the stated aims of Control Your Info -- to call attention to what critics say is an insecure Facebook environment -- but thinks the group acted unethically in hijacking groups. Still, he believes that Facebook probably will make the relatively easy, nontechnical changes necessary to prevent the hijackings.

Facebook defended its practices. "Security is a top priority for Facebook, and we devote significant resources to helping our users protect their accounts and information," according to a spokesperson. "Any assertion to the contrary is false. We think this focus on security is a major reason Facebook was recently named one of the top 10 most trusted companies in an independent survey conducted by TRUSTe and the Ponemon Institute." (continued...)

1  |  2  |  Next Page >

 

Tell Us What You Think
Your Comment:



Advertisement


 Network Security
1.   China Cyberattacks: Pervasive Threat
2.   Patch Tuesday Will Tie MS Record
3.   Cybersecurity Appears Hot for 2010
4.   EPIC Objects To Google-NSA Ties
5.   Torrent Traps Used To Harvest Logins


advertisement
EPIC Objects To Google-NSA TiesEPIC Objects To Google-NSA Ties
Cyberattack meant to rattle Google?
Average Rating:
Torrent Traps Used To Harvest LoginsTorrent Traps Used To Harvest Logins
Web sites sold with backdoor access.
Average Rating:
Social Networks: A Hacker's DelightSocial Networks: A Hacker's Delight
Workers urged to be 'trained skeptics.'
Average Rating:


advertisement
Product Information and Resources for Technology You Can Use To Boost Your Business

Mobile Enterprise Spotlight
Analysts See iPad Price Drop, with Some Cannibalization
Just weeks before Apple officially rolls out the iPad, financial analysts are making pricing predictions. But could the analysis itself hinder the initial demand for the pricey tablet computer?
 
Bar Codes Go Mobile, Get Hip Again
For decades, retailers have used patterns of black dots and lines to encode data onto products. Now, bar codes are gaining favor as an easy way for cell-phone users to view ads and other data instantly.
 
'Dead Simple, Dirt Cheap' JooJoo Tablet Shipping Soon
The JooJoo, a web-browsing tablet device that is the subject of a high-profile legal dispute, appears on track to reach buyers at the end of February, but the tablet scene has dramatically changed.
 

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Spam & Hackers | Security Products | Mobile Security | Windows Security | Data Security
EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.