2 楼
Facebook hack – how did this breach happen
Here's how it worked...
Facebook's systems were compromised through the 'View As' feature
'View As' lets you see your profile as another specific user would see it
The three bugs related specifically to a re-design of the video uploader
When using 'View As', the video uploader tool shouldn't have shown up at all
But on specific posts encouraging people to post happy birthday greetings,
it did show up
The second bug was that the video uploader incorrectly used Facebook's
single sign-on functionality, and generated an access token for the mobile
The third bug was that when the video uploader showed up, the access token
was generated for not you as the user, but for the user you were looking up
This was discovered by attackers, who were able to use this system to look
up other users and get further tokens
Facebook hack – how did this breach happen
Here's how it worked...
Facebook's systems were compromised through the 'View As' feature
'View As' lets you see your profile as another specific user would see it
The three bugs related specifically to a re-design of the video uploader
When using 'View As', the video uploader tool shouldn't have shown up at all
But on specific posts encouraging people to post happy birthday greetings,
it did show up
The second bug was that the video uploader incorrectly used Facebook's
single sign-on functionality, and generated an access token for the mobile
The third bug was that when the video uploader showed up, the access token
was generated for not you as the user, but for the user you were looking up
This was discovered by attackers, who were able to use this system to look
up other users and get further tokens
3 楼
第三个现在 fix 了么。。。
【在 d********f 的大作中提到】
: 感觉非常业余阿
: Facebook hack – how did this breach happen
: Here's how it worked...
: Facebook's systems were compromised through the 'View As' feature
: 'View As' lets you see your profile as another specific user would see it
: The three bugs related specifically to a re-design of the video uploader
: tool
: When using 'View As', the video uploader tool shouldn't have shown up at all
: But on specific posts encouraging people to post happy birthday greetings,
: it did show up
【在 d********f 的大作中提到】
: 感觉非常业余阿
: Facebook hack – how did this breach happen
: Here's how it worked...
: Facebook's systems were compromised through the 'View As' feature
: 'View As' lets you see your profile as another specific user would see it
: The three bugs related specifically to a re-design of the video uploader
: tool
: When using 'View As', the video uploader tool shouldn't have shown up at all
: But on specific posts encouraging people to post happy birthday greetings,
: it did show up
5 楼
这个垃圾网站 我注销好多年了 还成天往我信箱塞建议
【在 d********f 的大作中提到】
: 感觉非常业余阿
: Facebook hack – how did this breach happen
: Here's how it worked...
: Facebook's systems were compromised through the 'View As' feature
: 'View As' lets you see your profile as another specific user would see it
: The three bugs related specifically to a re-design of the video uploader
: tool
: When using 'View As', the video uploader tool shouldn't have shown up at all
: But on specific posts encouraging people to post happy birthday greetings,
: it did show up
【在 d********f 的大作中提到】
: 感觉非常业余阿
: Facebook hack – how did this breach happen
: Here's how it worked...
: Facebook's systems were compromised through the 'View As' feature
: 'View As' lets you see your profile as another specific user would see it
: The three bugs related specifically to a re-design of the video uploader
: tool
: When using 'View As', the video uploader tool shouldn't have shown up at all
: But on specific posts encouraging people to post happy birthday greetings,
: it did show up
6 楼
7 楼
12 楼
13 楼
【在 d********f 的大作中提到】
: 感觉非常业余阿
: Facebook hack – how did this breach happen
: Here's how it worked...
: Facebook's systems were compromised through the 'View As' feature
: 'View As' lets you see your profile as another specific user would see it
: The three bugs related specifically to a re-design of the video uploader
: tool
: When using 'View As', the video uploader tool shouldn't have shown up at all
: But on specific posts encouraging people to post happy birthday greetings,
: it did show up
【在 d********f 的大作中提到】
: 感觉非常业余阿
: Facebook hack – how did this breach happen
: Here's how it worked...
: Facebook's systems were compromised through the 'View As' feature
: 'View As' lets you see your profile as another specific user would see it
: The three bugs related specifically to a re-design of the video uploader
: tool
: When using 'View As', the video uploader tool shouldn't have shown up at all
: But on specific posts encouraging people to post happy birthday greetings,
: it did show up
15 楼
【在 d********f 的大作中提到】
: 感觉非常业余阿
: Facebook hack – how did this breach happen
: Here's how it worked...
: Facebook's systems were compromised through the 'View As' feature
: 'View As' lets you see your profile as another specific user would see it
: The three bugs related specifically to a re-design of the video uploader
: tool
: When using 'View As', the video uploader tool shouldn't have shown up at all
: But on specific posts encouraging people to post happy birthday greetings,
: it did show up
【在 d********f 的大作中提到】
: 感觉非常业余阿
: Facebook hack – how did this breach happen
: Here's how it worked...
: Facebook's systems were compromised through the 'View As' feature
: 'View As' lets you see your profile as another specific user would see it
: The three bugs related specifically to a re-design of the video uploader
: tool
: When using 'View As', the video uploader tool shouldn't have shown up at all
: But on specific posts encouraging people to post happy birthday greetings,
: it did show up
18 楼
上海市民50万买100寸彩电 6小时悬吊入户花费2万多(图)听说猎人x猎人下个月要重新连载了笑料百出2民主党新星与6个月大婴儿发生性关系被抓器人的冷笑话孔令辉这是侮辱大众智商吗? (转载)再看数学考了零分。零分就零分,录取北宋第一武功高手:武二郎 (转载)女子裸曬私處遭螃蟹誤認成生蠔夾傷 (转载)搞笑图片0193真心搞不懂柯杰输棋为什么要哭?想当年卡斯帕罗夫 (转载)版宠/群宠的几大特点 (转载)Re: 这两个部长不是一个国家的吧? (转载)女人与政治:这句话是什么意思?全副武装!英国上千名士兵进驻 伦敦进入紧急状态zz (转载)笑料百出3搞笑图片0188将军们,这样翻译地名才是真正的天朝崛起的风范! (转载)freedom fighters老将搞人海战术、八个团围攻虎肉一个人 (转载)