Get a Pentest and security assessment of your IT network.

Cyber Security

Facebook EXE attachment Vulnerability can Compromise with Users Security

Facebook EXE attachment Vulnerability can Compromise with Users Security. It can easily attach EXE files in messages, causing possible User Credentials to be Compromised. Note, you do NOT have to be friends with the user to send them a message with an attachment. The vulnerability was discovered by Nathan Power from SecurityPentest. It was discovered the variable ‘filename’ was being parsed to determine if the file type is allowed or not. To subvert the security mechanisms, we modified the POST request by appending a space to our filename variable like so:

Source: https://thehackernews.com/2011/10/facebook-exe-attachment-vulnerability.html

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security