Facebook Bug Lets Hackers Delete Friends
swandives writes "There's lot of talk about Facebook and privacy at the moment, but a bug in Facebook's website lets hackers delete Facebook friends without permission. Steven Abbagnaro, a student from Marist College in Poughkeepsie, New York, reported the flaw, writing proof-of-concept code that scrapes publicly available data from users' Facebook pages and deletes all of their friends, one by one. The victim first has to click on a malicious link while logged into Facebook. Abbagnaro's code exploits the same underlying flaw that was first reported by Alert Logic security analyst M.J. Keith who discovered a cross-site request forgery bug, where the website doesn't properly check code sent by users' browsers to ensure that they were authorized to make changes on the site."
How soon can I get them out of the picture, if you know what I mean.
"It's a feature."
Thats one hell of a bug. I didn't know you could do that much damage with php.
http://michaelsmith.id.au
In case you didn't RTFA, you can only delete the link between your facebook accounts, not the friends themselves.
And so dies our intricate plan to befriend our enemies and erase them from existance.
It was ... the hackers ... yes, that's it, it was the hackers that must have made everyone defriend me.
Imho the easiest way to get rid of facebook ;-)
I deleted my Facebook account a week or so ago, and I was, at the time, hoping that diaspora would end up being something besides vaporware. After a week without it, though, I find myself pleased with my lack of knowledge about what people I didn't like in high school had for dinner.
How soon can I get them out of the picture, if you know what I mean.
Sorry but I don't think the hack goes as far as photoshopping your pictures to erase your friends from them.
You can do anything with PHP.
The CSRF bug page in the summary says that facebook confirmed that it's patched already. And the actual hacker's page says that he found if he does a little more (delete a few more parameters as well as the "post_form_id"), the CSRF resurfaces.
Anyway, he posted an update saying fb patched this one now (22 May)..
I'm much more funny, interesting and insightful than the moderators think
It's not PHP's fudemental flaw that deletes your facebook friends, it's the programmer's bad authentification design.
The article seems to be directed at facebook, but it sounds to me like there needs to be a browser or OS exploit first in order to work: "combine an exploit for this bug with spam or even a self-copying worm code". I'm not a facebook user (get off my lawn), but a lot of XSS flaws are browser specific and if there is a general browser exploit going on, this could affect more websites than facebook. TFA just sounds a little misdirected to me.
boycott slashdot February 10th - 17th check out: altSlashdot.org
It's hard to tell if your friends have been affected by this 'bug'. If someone unfriends you then you might never know, yet when you add a new one it's all over everyone else's page
you need to look up
http://en.wikipedia.org/wiki/Seam_carving
there is an online app, http://rsizr.com/
and also gimp support http://liquidrescale.wikidot.com/
there should be some really cool videos http://www.google.com.au/search?q=seam+carving&tbs=vid:1
... delete an account from facebook!
As long as an Article is properly written, I don't mind if one lead case example of a flaw is used to get people's notice. "Flaw allows people to delete Facebook friends" will wake up more people than "missing parameter bug found in certain browsers".
I'm right on that borderline of a modestly aware of these issues, so when one surfaces that's "important to the masses" I like having a tagline in my mind to explain it with. I admit I ignore a lot of Linux kernel reports etc. My attitude to Linux is "it sorta is what it sorta is". The standards of my knowledge are far lower than Windows where I have to support other folks.
My first Journal Entry ever, in 8 years! http://slashdot.org/journal/365947/aphelion-scifi-fantasy-horror-poetry-webzine
Hackers have friends???
Friends let friends delete friends from Facebook.
After the bug deletes all your friends... Tom is added.
He was feeling all left out when everyone left myspace.
That's so people can delete people without being overcome by guilt. MySpace was exactly the same. Pretty much every site is. But there's a Greasemonkey script you can use, Facebook Friend Checker, if you want to know about such things.
-Clio
Karma: Bad (mostly from not giving a fuck)
Blog: http://clintjcl.wordpress.com
Now that's is what I call a Friend with Benefit.
Life takes interesting turns, but the most interest is when you're off the beaten path.
The victim first has to click on a malicious link while logged into Facebook.
I won't be sinking investment capital into the new countermeasures just yet. This is the same survival-of-the-least-retarded that was in effect when all the computer resource whores stopped running antivirus apps in the first place.
You only feel guilt when someone knows you did something wrong*, not just when you do something wrong*?
I hope "don't want to make other people feel bad" would be a better description.
* Not that unfriending someone on a website is "wrong" in the first place, but that's already being implied by using the word "guilt".
You need to grow a pair and learn to properly use systems. Facebook is bigger than ever, and it certainly isn't dying. And if you're seeing ads, I question why you don't take the 1 minute to install AdBlock, but take 1 minute to complain about ads on facebook. You're just a whiny baby as AFAIK.
-Clio
Karma: Bad (mostly from not giving a fuck)
Blog: http://clintjcl.wordpress.com
May we suggest the name "KipDrordy" for the bug?
Somewhat OT, but yesterday I took a look at FB and was redirected to this myspace page. Not myspace.com, but someone's actual page. This was around noon yesterday and lasted a couple hours. Oddly, this page is not in my firefox history, but instead shows up as myspace.com. I live in Chicago & have ATT DSL. Any clues???
We have also received reports that this exploit can be used to: delete all the user's files! and mess up their desktop really bad!
HACKERS DO NOT WORK THAT WAY.
All your face are belong to us!
I didn't delete you as a friend. And now the system won't let me add you back. Damn those evil, evil hackers!
Bark less. Wag more.
One more reason to use the AntiSocial Facebook app:
http://apps.facebook.com/antisocialnetworking/index.php
Wake me up when a FB exploit is discovered that actually removes all the data I ever put into their site, and genuinely deletes my account.
Reply to That ||
Facebook has fixed the flaw: http://www.itworld.com/security/108711/facebook-fixes-bug-allowed-friend-deletion
Do I care? Not really....
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
At least now I have an excuse available after I purge my Friends list...
So that's why my ex girlfriend deleted me off her page. Umm... yeah that has to be it.
... You have 0 Friends.
I wonder how long before someone writes an app that connects Facebook friend deletion events with Photoshop's Content-aware Fill feature... They could name the app "Stalin".
One more reason to use the AntiSocial Facebook app: http://apps.facebook.com/antisocialnetworking/index.php
For those of us who don't have Facebook accounts, please explain.
Ah, Ha! Found you!
Lasagne!!!!