exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Packet Storm Advisory 2013-0621 - Facebook Information Disclosure

Packet Storm Advisory 2013-0621 - Facebook Information Disclosure
Posted Jun 21, 2013
Authored by Todd J. | Site packetstormsecurity.com

Facebook suffered from an information disclosure vulnerability. If a user uploaded their contacts to Facebook and then proceeded to download their expanded dataset from the DYI (Download Your Information) section, they would receive a file called addressbook.html in their downloaded archive. The addressbook.html is supposed to house the contact information they uploaded. However, due to a flaw in how Facebook implemented this, it also housed contact information from other uploads other users have performed for the same person, provided they had one piece of matching data. This effectively built large dossiers on users and disclosed their information to anyone that knew at least one piece of matching data.

tags | exploit, info disclosure, packet storm
SHA-256 | 07268c0e796ea6d21e794a4db3101dd9e38d23de66ebb9b581bb627fba66c532

Packet Storm Advisory 2013-0621 - Facebook Information Disclosure

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


+------------------------------------------------------------------------------+
| Packet Storm Advisory 2013-0621 |
| http://packetstormsecurity.com/ |
+------------------------------------------------------------------------------+
| Title: Facebook Information Disclosure |
+--------------------+---------------------------------------------------------+
| Release Date | 2013/06/21 |
| Advisory Contact | Packet Storm (advisories@packetstormsecurity.com) |
| Researcher Credit | Michael Fury |
+--------------------+---------------------------------------------------------+
| System Affected | Facebook (www.facebook.com) |
| Vendor Patched | 2013/06/16 (based on our testing) |
+--------------------+---------------------------------------------------------+

+----------+
| OVERVIEW |
+----------+

Facebook suffered from an information disclosure vulnerability.

- -----------------------------------------------------------------------------

+---------+
| DETAILS |
+---------+

If a user uploaded their contacts to Facebook and then proceeded to
download their expanded dataset from the DYI (Download Your Information)
section, they would receive a file called addressbook.html in their
downloaded archive. The addressbook.html is supposed to house the
contact information they uploaded. However, due to a flaw in how
Facebook implemented this, it also housed contact information from
other uploads other users have performed for the same person, provided
they had one piece of matching data. This effectively build large dossiers
on users and disclosed their information to anyone that knew at least
one piece of matching data.


- -----------------------------------------------------------------------------

+------------------+
| PROOF OF CONCEPT |
+------------------+

1. Dan has an account with Facebook and has registered with dan@freemail.xy

2. Alice uploads her contact information to Facebook. In it there is an
entry for Dan with phone numbers 408-555-1212, 408-555-3433, and email
addresses dan@freemail.xy and dan@datingsite.xy

3. Bob uploads his contact information to Facebook. In it there is an entry
for Dan with phone number 408-555-9999 and email addresses dan@freemail.xy
and dan@danswork.xy

4. Eve pulls Dan's dan@freemail.xy email address off of his blog, adds it
to a vcf file, and uploads it to Facebook. She then downloads her
expanded dataset. The addressbook.html file would now contain an entry
for Dan with phone numbers 408-555-1212, 408-555-3433, 408-555-9999
and email addresses dan@freemail.xy, dan@datingsite.xy, and dan@danswork.xy.


- -----------------------------------------------------------------------------

+-------------+
| REMEDIATION |
+-------------+

Facebook quickly reacted and addressed the disclosure issue. Erroneously
included data was purged and the broken functionality was fixed. During the
entire process, Packet Storm had an open dialog with them and to their credit,
they were honest with us and paid the finder an appropriate bug bounty.

The one issue not addressed is that Facebook will not give you control
over data tied to your account if uploaded by another individual. They
claim that your friends own your personally identifiable information when
they upload it, not you. However, given that Facebook is mapping this (and
even if they have stopped, they clearly have this ability), Packet Storm
feels they are not providing adequate controls for users to protect themselves
from this sort of disclosure happening again. Please visit the editorial
and Facebook links below for additional information.

- -----------------------------------------------------------------------------

+---------------+
| RELATED LINKS |
+---------------+

Packet Storm Editorial:
http://packetstormsecurity.com/news/view/22713/Facebook-Where-Your-Friends-Are-Your-Worst-Enemies.html

Facebook Security:
http://www.facebook.com/security/notes


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFRxMj9rM7A8W0gTbERAtMeAJ4758eT/34qQh2EFma6y2yZMJt7lQCgsJVG
6lRoqwOnb3AsIlVN9HNkCaM=
=lUY2
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    50 Files
  • 15
    Aug 15th
    33 Files
  • 16
    Aug 16th
    23 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    43 Files
  • 20
    Aug 20th
    29 Files
  • 21
    Aug 21st
    42 Files
  • 22
    Aug 22nd
    26 Files
  • 23
    Aug 23rd
    25 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close