Posted by : Unknown Rabu, 09 Januari 2013

An independent vulnerability researcher, Sow Ching Shiong, found a way to change the password of any facebook username without knowing his last password. Facebook have fixed this very critical vulnerability. This flaw allow an attacker to change any facebook user's password easily.



Facebook have a recovery page for compromised accounts "https://www.facebook.com/hacked". when clicked, it redirected to another page
"https://www.facebook.com/checkpoint/checkpointme?f=[userid]&r=web_hacked"
the parameter f equals to the user id, if any user id is given, password can be changed without any proper authentication.





The vulnerability was very simple to execute. This vulnerability has been confirmed and patched by Facebook Security Team.

Description: Facebook password reset vulnerability found by a security researcher
Rating: 4.5
Reviewer: Unknown
ItemReviewed: Facebook password reset vulnerability found by a security researcher

Leave a Reply

Monggo Tinggalkan Jejak Kaks :)

Subscribe to Posts | Subscribe to Comments

Welcome to My Blog

Popular Post

Labels

Arsip Blog

Followers

- Copyright © 2013 shad0w-share | Designed by Johanes Djogan -