Thursday, November 24, 2011

How does facebook Self XSS works ??



If you are a facebook user , you may have definitely came across video posts on your wall that have a  title and an innocent thumbnail but upon clicking, the link redirects  you to a scam website. 

How does those links came on your wall ??? , Does that particluar person's account is hacked ?? or does he his PC contains virus which is posting those malicious links on his friends wall ??? 


Matt Jones, who works with the Data & Security team at Facebook, walks us through the various type of scams that happen on Facebook.com and why do they happen?? . Most scams require Facebook users to copy-paste some JavaScript code into the browser's address bar and as soon as they do that, the rogue post is automatically published to the walls of all their Facebook friends.

Facebook Self XSS 


According to Matt, Google Chrome and Safari are the only browsers that are susceptible to this kind of cross-site scripting (XSS) vulnerability while IE and Firefox are relatively safe. And since the malicious JavaScript code is often hidden inside Flash videos, Facebook isn’t able to detect it. 

0 comments:

Twitter Delicious Facebook Digg Stumbleupon Favorites More

 
Design by Vamshi krishnam raju | Bloggerized by Vamshi krishnam raju - Vamshi krishnam raju | Vamshi krishnam raju