Social Networking Sites Full of Security Holes 76
athloi writes "Social networking Web sites such as MySpace.com are increasingly juicy targets for computer hackers, who are demonstrating a pair of vulnerabilities they claim expose sensitive personal information and could be exploited by online criminals."
Hey...Wait a minute (Score:5, Funny)
Now, so many holes in social networking sites your data is already in the hands of criminals.
Re:Hey...Wait a minute (Score:4, Funny)
"It's Time for Social Networks to Open Up" (Score:5, Funny)
Hey, site vulnerabilities are an API! Right?
XSS is Web 3.0.
Re: (Score:1)
Re: (Score:1)
Re: (Score:2)
Re: (Score:2)
Re:Hey...Wait a minute (Score:5, Informative)
In the end it's hardly surprising. These sites aren't designed with security in mind, and they allow user code on the pages. Game over man, game over. Blah blah blah SSL, blah blah blah strong passwords, blah blah blah restrict user code...This stuff is all basic.
Re: (Score:1)
Re: (Score:2)
My God....It's full of holes! (Score:5, Funny)
Of course it's full of holes. How else would it connect to the series of tubes?
Re:My God....It's full of holes! (Score:4, Funny)
I'd say the real threat isn't holes, but ho's (Score:5, Insightful)
Re:I'd say the real threat isn't holes, but ho's (Score:4, Insightful)
The other day i could watch a demonstration of a XSS attack on meebo due to lack of server-side validation.
Now add a little AI / data mining to this:
(New entry, mo/day/yr) "Here's a picture of me and my daughter Jessica playing on the NN. park" -> AI -> name: Jessica. Picture: (insert here). Last seen on: MMDDYY. Location: NN. Park.
There! You could make a database of potential victims for threats, blackmailing, and what not. The only thing that makes me feel safe is that such AI data mining technology hasn't been developed... yet.
As a rule of thumb, follow Murphy's law: What can go wrong, WILL go wrong (remember the recent SSN leaks?) Unless social networking sites have been PUBLICLY certified as having greater security than Fort Knox, stay away.
Re: (Score:2)
Nah, you look more like you did in that faked YouTube video where you had a pineapple shoved up your butt.
At least I'm *assumuing* it was faked...
Re: (Score:2)
Perhaps ran into one of these (Score:1, Interesting)
Re:Perhaps ran into one of these (Score:4, Informative)
Not much you can do about it other than turn of javascript by default. It's pretty annoying actually...These vulnerablities have been known forever, but patching them would break a lot of code, so they stay open.
Re: (Score:2, Insightful)
Re: (Score:1)
Re: (Score:2)
Re: (Score:2)
http://msdn2.microsoft.com/en-us/library/ms533046. aspx [microsoft.com]
http://www.petefreitag.com/item/644.cfm [petefreitag.com]
of course, new rushed in features open nice juicy vectors
http://ha.ckers.org/blog/20070719/firefox-implemen ts-httponly-and-is-vulnerable-to-xmlhttprequest/ [ckers.org]
Applause (Score:1, Funny)
Whew! I'm Glad I'm a 15-year-old girl! (Score:5, Funny)
At least I don't think they can get to me!
Re:Whew! I'm Glad I'm a 15-year-old girl! (Score:5, Funny)
And your little dog, too.
don't worry (Score:1, Funny)
Re: (Score:2)
A Net is a Bunch of Holes Sewn Together (Score:4, Insightful)
i wouldn't be surprised (Score:5, Insightful)
Re: (Score:2, Insightful)
Some of these can porbably be answered by anyone reading the profile or blog of someone else; and once you got access to the email-account, you could use the forgot-password-option on almost all other websites, including ebay and paypal.
Re: (Score:1)
Re: (Score:1)
I know, and they keep sending me Friend requests (Score:3, Funny)
Oh, wait a second, you said 'Holes'. Oh. Carry on, then...
Security Holes? (Score:1, Funny)
perverts? (Score:2, Funny)
No SSL (Score:3, Insightful)
'increasingly juicy targets' (Score:2)
/haven't tried, myself
Stereotyping? (Score:5, Insightful)
Just a LITTLE bit of stereotyping in the article title I think?
Re: (Score:2)
They really don't care about the end user... (Score:2, Insightful)
What I find funny is the fact that most of the poor souls that go to such sites looking to connect with other people are on a site where the people in charge couldn't care less... I signed up for My(waste of)Space when it showed up on the net because for some people I knew it was the only means to reach them any longer. I canceled my ISP and switched since then, asking the OZ like people running the show to please update my e-mail to reflect this change, more than a year has gone by. Has my e-mail been chan
Re: (Score:1)
Re: (Score:1)
To play devil's advocate, how could they reasonably have differentiated you from a malicious user intent on subverting someone else's account?
Erm, since I was actually logged into the account and provided everything they had asked for it might have been grounds for them to approve such a request thereby proving my identity... But then again you are right, from the eyes of the truly security conscious there is no way. Be sure I won't be e-mailing or faxing anybody a copy of my ID anytime soon, let alone divulging personal information on the internet to anybody in the name of security or not. Disturbing in the digiworld there is no real way for yo
Full of holes? No problem... (Score:5, Funny)
I'm sure Tom will get right on it.
Re: (Score:1)
A patch has been issued (Score:1, Funny)
Myspace hole that's funny (Score:3, Informative)
Then there was the time I was on myspace, and a banner ad tried to send me a virus. You would think Myspace would be a bit more discretionary who it lets send banners over. Tsk tsk!
Of course, not as fun as the images directory being left open on all angelfire pages. Some of those were fun to sort through, showing pictures not intended for the public(ie nudity, etc).
News? (Score:2)
But Celebrities are doing it... (Score:1)
user-submitted HTML content bad (Score:2, Insightful)
That's not nice to the girls. (Score:2)
Oh we're talking about security? My bad.
Try Deleting Your Facebook Account (Score:2, Informative)
Stop the presses! (Score:1)
What sort of fiend would pray on people who clearly state there name, address, age, and often occupation, hangouts, favorite things.
I mean really, how much security did you expect. There is no anonymity on Myspace or Flicker, so who the hell would be surprised when it gets hacked. There are probably a million people out there that hate Myspace (or flicker/other social sites) some of them must have t
MySpace is the boogeyman (Score:1)
And now you go and post this? Despite th