Exploiting a Cross-site Scripting (XSS) vulnerability on Facebook

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
14,196
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Jul 27, 2010

The following video shows how an attacker may exploit a cross-site scripting vulnerability on Facebook.com regardless of the HTTPOnly cookie protection used. Of course, this goes way beyond showing an "alert()" popup in Javascript, since the attacker is also able to hijack the victim's Facebook account. We also published an article to explain in more technical detail the works behind abusing such a flaw.

http://www.acunetix.com/websitesecurity/xss-facebook.htm

Facebook rates as the second most popular website on the internet with 400 million active users. When such a website has common web application security flaws, they are going to be abused for one's gain. When we came across an obvious cross-site scripting vulnerability, we decided to show that an attacker could do that.

We worked with Facebook to make sure that this vulnerability is fixed. We would like to thank their security team for quickly fixing it.

For more information visit http://www.acunetix.com

  • likes, 2 dislikes

Link to this comment:

Share to:
see all

All Comments (4)

Sign In or Sign Up now to post a comment!
  • VERY nice :) another good way/easy was it to run SET/metasploit clone attack that looks like the facebook login page, they'll think they got signed out and log back in giving you their user/pass

  • Nice Coding to iframe hijack

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more