Facebook, Twitter account hack detailed
An exploit in the Facebook-owned Face.com mobile app, KLIK, has been fixed after a researcher found that it could be used to hijack Facebook and Twitter accounts.
The KLIK app lets people tag faces in photos using Facebook.
The security hole was found by Ashkan Soltani, a privacy and security researcher, who claimed the hack allowed anyone to gain access to private Facebook photos.
“The above attack not only allows access to non-public photos, but also lets the attacker potentially manipulate the Face.com app to automatically ‘recognize’ anyone walking down the street (i.e just hijack Lady Gaga’s account and get her ~11 million friends’ ‘face prints’),” Soltani said on his blog.
“Since KLIK relies on Facebook connect, that means anyone that has used the app was vulnerable,” he continued.
The problem was caused by Face.com’s insecure storage of Facebook and Twitter OAUTH authorization tokens.
Read the full story at: Cnet.
Related articles:
Facebook to buy facial-recognition startup
Facebook settles R82.7 million lawsuit