Facebook Bug Lets Hackers Delete Friends
swandives writes "There's lot of talk about Facebook and privacy at the moment, but a bug in Facebook's website lets hackers delete Facebook friends without permission. Steven Abbagnaro, a student from Marist College in Poughkeepsie, New York, reported the flaw, writing proof-of-concept code that scrapes publicly available data from users' Facebook pages and deletes all of their friends, one by one. The victim first has to click on a malicious link while logged into Facebook. Abbagnaro's code exploits the same underlying flaw that was first reported by Alert Logic security analyst M.J. Keith who discovered a cross-site request forgery bug, where the website doesn't properly check code sent by users' browsers to ensure that they were authorized to make changes on the site."
I deleted my Facebook account a week or so ago, and I was, at the time, hoping that diaspora would end up being something besides vaporware. After a week without it, though, I find myself pleased with my lack of knowledge about what people I didn't like in high school had for dinner.
It's hard to tell if your friends have been affected by this 'bug'. If someone unfriends you then you might never know, yet when you add a new one it's all over everyone else's page
... delete an account from facebook!
Everything today is "a feature". Real tired to hear these "problems" - not really problems but laziness, ignorance, whatever by developers / designers! Yes, the base, the standards, the tools, and so on are flawed but nothing says the systems have to be coded that way, allowing all the security and other problems. I have tried a long time to defend the developers - it wasn't their problem that that their tools, toys, systems, etc were bad but after so long - anyone anymore creating systems with these flaws is to blame!
This is really getting out of hand - why would anyone build systems which allow these problems, cross-site without checking, whatever - on purpose? Sorry, after 30+ years designing / creating safe systems for global mission critical operations, public safety, etc - I just can't understand!! Yes - sometimes it means fighting the management and even customer but why would anyone do it - every time it comes back haunting you, badly! What has happened to separation of presentation, processing, authentication, authorization, etc?? The basic rules in safe computing! Or did your vendor licensing book forget to tell you about the bad and ugly world outside the door? If so - why not start thinking yourself?
I didn't delete you as a friend. And now the system won't let me add you back. Damn those evil, evil hackers!
Bark less. Wag more.
It is not XSS, but CSRF. Cross-site request forgery. Such exploits are designed to exploid the way site processes user inputs. If site uses custom forms or request fields, exploit will work only on this site and in most of the cases it is not specific to some browser.