Hackers Can Hijack your Facebook account using Android flaw. Learn - TopicsExpress



          

Hackers Can Hijack your Facebook account using Android flaw. Learn How! (BTW) This is old.... the OLD attack spam that we saw many times here on fb that the accounts was used to attack groups and profiles friends in a massive spam attack Facebook Users Targeted By Android Same Origin Policy Exploit A few months back, we discussed the Android Same Origin Policy (SOP) vulnerability, which we later found to have a wider reach than first thought. Now, under the collaboration of Trend Micro and Facebook, attacks are found which actively attempt to exploit this particular vulnerability, whose code we believe was based in publicly available Metasploit code. This attack targets Facebook users via a link in a particular Facebook page that leads to a malicious site. This page contains obfuscated JavaScript code JavaScript code could allow an attacker to perform various tasks on the victim’s Facebook account, on behalf of the legitimate account holder. According to the researcher, hackers can do almost anything with the hacked Facebook account using JavaScript code. Some of the activities are listed as follows: Adding Friends Like and Follow any Facebook page Modify Subscriptions Authorize Facebook apps to access the user’s public profile, friends list, birthday information, likes. To steal the victim’s access tokens and upload them to their server. Collect analytics data (such as victims’ location, HTTP referrer, etc.) using the legitimate service. All Android devices upto Android 4.4 KitKat are vulnerable to this SOP vulnerability. However, a patch was offered by Google back in September, but millions of Android smartphones users are still vulnerable to the attack because the manufacturer of the smartphone no longer pushes the update to its customers or the device itself does not support a newer edition of the operating system. The SOP vulnerability resides in the browser of the Android devices, which cant be uninstalled because its usually part of the operating system in-build feature. So, in order to protect yourself, just Disable the BROWSER from your Android devices by going to Settings > Apps > All and looking for its icon. By opening it, you’ll find a DISABLE button, Select it and disable the Browser. blog.trendmicro/trendlabs-security-intelligence/facebook-users-targeted-by-android-same-origin-policy-exploit/
Posted on: Mon, 29 Dec 2014 11:49:43 +0000

Recently Viewed Topics




© 2015