+ Reply to Thread
Results 1 to 6 of 6
Like Tree3Likes
  • 3 Post By [s]

Thread: Facebook 3rd Part App Installing Page UI Redressing Vulnerability Share/Save - My123World.Com!

  1. #1
    [s]
    [s] is offline
    Security Researcher [s] will become famous soon enough [s]'s Avatar
    Join Date
    Nov 2010
    Posts
    187
    Blog Entries
    2
    Thanks
    62
    Thanked 53 Times in 30 Posts

    Facebook 3rd Party App Installing Page UI Redressing Vulnerability



    #Title: Facebook 3rd Part App Installing Page UI Redressing Vulnerability
    Author: Sandeep Kamble
    #Business Risk : Medium Risk
    #Attack Type: UI Redressing Vulnerability
    #Tested Browser: Firefox 3.6.27
    #OS: Win 7 / Linux
    #Reported Date: July 26 , 2011


    Summary
    GDay ! Recently , I have submitted UP Redressing Vulnerability to Facebook. Vulnerability enables attacker to install any 3rd Party malicious application into victim Facebook account.

    Overview
    Clickjacking (UI Redressing )is an exploit in which coding on a malicious website is hidden beneath apparently legitimate buttons.

    The strange part of this testing was Facebook 3rd party App installing page already protected for UI redressing vulnerability. The Protection is perfectly working on chrome , safari , IE & New Version of FF .

    But Facebook 3rd party App installing page UI redressing failed to work on Firefox 3.6.27. So in Firefox 3.6.27 i perfectly iframed page & made a perfect POC Facebook team.

    Code:
    Public POC :


    Special Thanks to FB team to fix this Bug ! My team G4h

    Thanks
    [S] - Sandeep
    Last edited by [s]; 08-04-2012 at 10:12 AM.
    b0nd, AnArKI and Globz like this.

    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

  2. The Following 2 Users Say Thank You to [s] For This Useful Post:

    "vinnu" (08-01-2012), b0nd (08-03-2012)

  3. #2
    Security Researcher fb1h2s has a spectacular aura aboutfb1h2s has a spectacular aura aboutfb1h2s has a spectacular aura about fb1h2s's Avatar
    Join Date
    Jul 2010
    Location
    India
    Posts
    596
    Blog Entries
    23
    Thanks
    279
    Thanked 150 Times in 76 Posts
    Good Job, any idea why the protection was not working on FF, some JS failure ? Do you have the previous Code with you to check how facebook dealt with this issue.
    Hacking Is a Matter of Time Knowledge and Patience

  4. The Following User Says Thank You to fb1h2s For This Useful Post:

    [s] (08-04-2012)

  5. #3
    [s]
    [s] is offline
    Security Researcher [s] will become famous soon enough [s]'s Avatar
    Join Date
    Nov 2010
    Posts
    187
    Blog Entries
    2
    Thanks
    62
    Thanked 53 Times in 30 Posts
    Quote Originally Posted by fb1h2s View Post
    Good Job, any idea why the protection was not working on FF, some JS failure ? Do you have the previous Code with you to check how facebook dealt with this issue.
    Yes , it was JS Failure ! I have confirmed with Facebook ! I don't have copy of the JS.

    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

  6. #4
    Web Security Consultant amolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really nice amolnaik4's Avatar
    Join Date
    Jul 2011
    Location
    webr00t
    Posts
    269
    Blog Entries
    3
    Thanks
    24
    Thanked 180 Times in 100 Posts
    very nice bug sandeep.... keep it up

  7. The Following User Says Thank You to amolnaik4 For This Useful Post:

    [s] (08-02-2012)

  8. #5
    [s]
    [s] is offline
    Security Researcher [s] will become famous soon enough [s]'s Avatar
    Join Date
    Nov 2010
    Posts
    187
    Blog Entries
    2
    Thanks
    62
    Thanked 53 Times in 30 Posts
    Quote Originally Posted by amolnaik4 View Post
    very nice bug sandeep.... keep it up
    Thanks Amol , I remember your Click Jacking Talk of Null

    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

  9. #6
    Garage Newcomer Globz is on a distinguished road Globz's Avatar
    Join Date
    Sep 2011
    Posts
    17
    Thanks
    9
    Thanked 4 Times in 2 Posts
    Great find, keep it up bro!! Go G4H!
    When the way comes to an end, then change - having changed, you pass through


Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts