Home > Facebook > Facebook Attach EXE Vulnerability
Facebook Attach EXE Vulnerability
Posted on 28 Oktober 2011 by c0decstuff
1. Summary:
When using the Facebook 'Messages' tab, there is a feature to attach a file. Using this feature normally, the site won't allow a user to attach an executable file. A bug was discovered to subvert this security mechanisms. Note, you do NOT have to be friends with the user to send them a message with an attachment.
---------------------------------------------------------------------------------------------------------------------------
2. Description:
When attaching an executable file, Facebook will return an error message stating:
"Error Uploading: You cannot attach files of that type."
When uploading a file attachment to Facebook we captured the web browsers POST request being sent to the web server. Inside this POST request reads the line:
Content-Disposition: form-data; name="attachment"; filename="cmd.exe"
It was discovered the variable 'filename' was being parsed to determine if the file type is allowed or not.
To subvert the security mechanisms to allow an .exe file type, we modified the POST request by appending a space to our filename variable like so:
filename="cmd.exe "
This was enough to trick the parser and allow our executable file to be attached and sent in a message.
-------------------------------------------------------------------------------------------------------------------------
3. Impact:
Potentially allow an attacker to compromise a victim’s computer system.
-----------------------------------------------------------------------------------------------------------------------
4. Affected Products:
www.facebook.com
-----------------------------------------------------------------------------------------------------------------------
5. Time Table:
09/30/2011 Reported Vulnerability to the Vendor
10/26/2011 Vendor Acknowledged Vulnerability
10/27/2011 Publicly Disclosed
-----------------------------------------------------------------------------------------------------------------------
6. Credits:
Discovered by Nathan Power
www.securitypentest.com
Category Article Facebook
One Response to “c0decstuff”
Total Pageviews
Labels
- Android (1)
- Aplication (14)
- ARP (1)
- Backdoored (2)
- Browser (1)
- Cloud (1)
- Exploitation (1)
- Exploits (7)
- Facebook (2)
- forensics (3)
- Hacking (11)
- Hijacking (1)
- Honeypot (1)
- HTML5 (1)
- ios (2)
- Jailbreak (2)
- Linux (1)
- Malware (5)
- metasploit (2)
- Meterpreter (1)
- Movie (1)
- Networking (1)
- News (2)
- password attack (2)
- Penetration Test (2)
- Python (1)
- reverse engineering (1)
- Rootkits (1)
- Security (12)
- shellcode (2)
- Stuxnet/Duqu (2)
- Uncategories (1)
- Virus (1)
- Vulnerability (8)
- Web (5)
- Wifi (1)
- Windows (5)
Friendlist
Security Resources
-
-
-
This feed contains no entries
-
-
-
-
-
-
-
-
-
لو تريد الحصول على افضل خدمات تنظيف وتعقيم خزانات المياه وانت في جدة لا عليك الا ان تقوم بالتواصل مع افضل شركاتتنظيف خزانات المياه بجده بجدة التي تستخدم مواد تنظيف وتعقيم اصلية ومعتمدة وعندها ستجد انك وقعت على الاختيار الصحيح وستحصل على خدمات ممتازة لأن اعمال صيانه خزانات المياه بجده متنوعة وتشمل الصيانة الشاملة لخزان المياه خاصتك
وبخصوص اعمال التخلص من الحشرات داخل المنازل فنحن نعتبر افضل شركات مكافحة الحشرات بجدة متخصصة في القضاء على جميع انواع الحشرات الضارة