May 19, 2013

Firefox extension steals Facebook, Twitter, etc. sessions

Presented at ToorCon, Firefox extension Firesheep demonstrates how easy it is for attackers to access accounts belonging to other users on the same network, such as a Wi-Fi hotspot. After launching the program, user accounts belonging to other users gradually appear in the sidebar as users navigate to any of the many supported web sites, which currently include Facebook, Twitter, Flickr, Amazon, Windows Live and Google. By clicking on one of the sidebar entries (which generally display the victim’s name and photo), an attacker is able to access the site in question with all the legitimate user’s privileges.

Read the full story here.

Source:[TheHSecurity]

Facebook introduces one time passwords

[ad code=6 align=left]

Facebook lunched one-time password for non-secure computers in places like hotels, cafes or airports. The one-time password (OTP) will be sent to you as a text message If you have any concerns about security of the computer you’re using while accessing Facebook. Facebook can text you a one-time password to use instead of your regular password.

Simply text “otp” to 32665 on your mobile phone (U.S. only), and you’ll immediately receive a password that can be used only once and expires in 20 minutes. In order to access this feature, you’ll need a mobile phone number in your account. Facebook are rolling this out gradually, and it should be available to everyone in the coming weeks.

170 Million Data Sets from Facebook

Facebook directory at “facebook.com/directory” provides a directory of users who select to make their Facebook profiles public. Facebook creates a preview version of their profile which is accessible to anyone.

Facebook LogoH-Online.com has an interesting report by Chris von Eitzen about a Hacker who has written a web crawler which he used to systematically graze through facebook data. He has collected more than 170 million sets of data containing the names and URLs of public profiles. The files do not contain any other personal data such as friend lists, but the links in the profiles can easily be used to send out another crawler to collect other information. The crawler and collected data are available as a 2.8 GB torrent.

Facebook directory at “facebook.com/directory” provides a directory of users who select to make their Facebook profiles public. Facebook creates a preview version of their profile which is accessible to anyone.

H-Online.com has an interesting report by Chris von Eitzen about a Hacker who has written a web crawler which he used to systematically graze through facebook data. He has collected more than 170 million sets of data containing the names and URLs of public profiles. The files do not contain any other personal data such as friend lists, but the links in the profiles can easily be used to send out another crawler to collect other information. The crawler and collected data are available as a 2.8 GB torrent.