Facebook Bug Could Give Spammers Names, Photos
angry tapir writes with this excerpt from an IDG report: "Facebook is scrambling to fix a bug in its website that could be misused by spammers to harvest user names and photographs. It turns out that if someone enters the e-mail address of a Facebook user along with the wrong password, Facebook returns a special 'Please re-enter your password' page, which includes the Facebook photo and full name of the person associated with the address. A spammer with an e-mail list could write a script that enters the e-mail addresses into Facebook and then logs the real names. This could help make a phishing attack more realistic."
Seriously? Who is freaking writing these web pages? It would have been easier to NOT include photo's and names than to build it in there!
It's a feature. Say you get amnesia and all you remember is your email address. Now, thanks to Facebook, you have a means of finding out your name, and what you look like!
I'm a popular stranger, I'm nobody famous, I'm a famous nobody.
Fixing this alone means nothing. If you search for someone on Facebook it will show you a name and a profile picture. Sure, it requires a facebook account, but that's not too hard to create for somebody with 4,000,000 email addresses.
>>Scraping Facebook for this type of information is prohibited, she added.
Oh, yes. That'll stop em'. Stern warnings always do.
Huh?
This flaw is no longer available on Facebook logon pages.
In fact it was removed before this story made it to the /. front page.
It was removed approx. 11 hours after the first public articles about it.
- Jesper
My security clearance is so high I have to kill myself if I remember I have it...
Maybe it relies on a cookie or something, and it only shows that to you because you've been logged in before.
That does seem to be the case. I just tested it on two browsers, one of which I don't use with Facebook.
On the browser that I don't use with Facebook, the "Please enter your password" screen did not include a name or picture.
On the browser that I do use with Facebook, and had just logged out seconds before, my name and photo did appear. However, if I entered someone else's address, the name and photo did not appear. Just for kicks, I tried two email addresses, one of which I know does have an account and one of which I know doesn't. Facebook *did* tell me which one was not associated with an account.
A spammer isn't going to have your cookies, so they won't get your name and photo. But they can confirm whether you have a Facebook account or not.