• About EHN
  • Mobile Apps
  • Twitter
  • Contact Us
  • Blogger Tips
  • Infosec Jobs
  • PenTesting
  • Partners
  • eBook
  • Subscribe to my RSS
E Hacking News
  • EHN
  • Cyber Crime
  • Vulnerability
  • Malware
  • IT Security
  • Hacker News
  • Spam
  • Defacements
  • Database Leaked
Follow @EHackerNews
Showing posts with label Open Redirection vulnerability. Show all posts
Prakhar Prasad, a Web application security Researcher, has discovered Open Redirection vulnerability in the Facebook mobile website(m.facebook.com).

An open redirect is an application that takes a parameter and redirects a user to the parameter value without any validation. This vulnerability is used in phishing attacks to get users to visit malicious sites without realizing it

Usually, when you try to visit external links in facebook, the url will be passed to "l.php" page that will displays "Leaving Facebook" message before redirecting. So if it is malicious link, the page will show warning message.

But Prasad discovered one of the page in Facebook mobile redirects user directly to the external link.

POC:
http://m.facebook.com/video_redirect/?src=http://www.google.com
He found this vulnerability when he tried to view the uploaded video on Facebook mobile website.

Researcher immediately sent notification to Facebook about the vulnerability .  Facebook fixed the vulnerability and rewarded researcher with $500.
Older Posts Home
  • Recent Posts
  • Comments
Sponsored Links

Become a Fan

Funded by

Cyber Security and Privacy Foundation:


EHacking news is funded by Cyber Security and Privacy Foundation.
http://cysecurity.org

Get Latest news at Your Email

Enter Your Email:


    
TwitterAdd me in Google +
RSS Subscribe to our RSS Feeds!
TwitterFollow Us on Twitter!
Sponsored Links:
DMCA.com
  • Funny Forward Mails
  • Debugging Questions in Java
COPYRIGHT 2012 by EHN. | Read our Privacy Policy