Blog|Login|Chinese German Japanese|Follow @imperva
January 30, 2012
 Facebook Bug Hunting

BusinessWeek is running a great article on bug hunting by companies such as Facebook, Google and more.  One of the featured bug hunters is Imperva's Tal Be'ery.  Here's Tal's account of finding that particular problem with Facebook and how it was reported.

On the 29th of July, Imperva's ADC team was exploring the login mechanisms of several prominent web applications including Facebook.

We were hoping to learn about the adoption of advanced security mechanisms, but you can imagine how surprised we were when we found out that Facebook's registration process was performed over HTTP with no encryption at all – leaving all the registration details including the password exposed for an eavesdropper.

FB1

For the sake of brevity, some irrelevant HTTP headers were removed, but here are the relevant part of the POST parameters:

FB2

This was a violation of Facebook's current privacy policy:

We keep your account information on a secured server behind a firewall. When you enter sensitive information (such as credit card numbers and passwords), we encrypt that information using secure socket layer technology (SSL).

Moreover, it was a risk to the privacy of Facebook's user base, about 500M at that time.

After we made sure that the violation is indeed valid and not an artifact of our testing environment, we reported the issue to Facebook.  They had acknowledged the security vulnerability and fixed it by August 15th.


Comments

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.

« Massive Virus Hits Android | Main | The FBI's Social Media Monitoring »