Saturday, September 1, 2012

Suspected LulzSec member arrested by FBI for Sony Pictures hack.

A man suspected of hacking into computer systems belonging to Sony Pictures, and stealing the personal information and passwords of thousands of innocent internet users, has been arrested by the FBI.
20-year-old Raynaldo Rivera, of Tempe, Arizona, is said to have been involved in the Sony hack last year that exposed online the names, birth dates, addresses, emails, phone numbers and passwords of people who had entered Sony contests.

Sunday, January 8, 2012

Symantec's Norton AntiVirus source code exposed by hackers.


Symantec, the makers of Norton AntiVirus, has confirmed that a hacking group has gained access to some of the security product's source code.
An Indian hacking group, calling itself the Lords of Dharmaraja, has threatened to publicly disclose the source code on the internet.
So far, there have been two claims related to Symantec's source code.
First, a document claiming to be confidential information related to Norton AntiVirus's source code was posted on Pastebin. Symantec says it has investigated the claim, and that - rather than source code - it was documentation dated from April 1999 related to an API (application programming interface) used by the product.
And secondly, the hacking group shared source code related to what appears to have been the 2006 version of Symantec's Norton AntiVirus product with journalists from Infosec Island.
A hacker called "Yama Tough", who appears to be acting as a spokesperson for the gang, posted the content to PasteBin.
The content on PasteBin has since been removed, and Yama Tough's Google+ posts deleted. The hackers claim that it is working on creating mirror sites for its content, as it has felt pressured and censored by US and Indian government agencies.
It's important to underline that there is presently no reason to believe that Symantec's own servers have been breached.
Instead, it appears that the data leak may have occurred on Indian government servers - and the implication is that Symantec, and perhaps other software companies, may have been required to supply their source code to the Indian authorities.
Furthermore, it is not clear if the source code which was accessed is relevant to up-to-date installations of Symantec's anti-virus products and thus customers may not be at risk.
Even if it was up-to-date source code, it may be of limited use to hackers and be used more as a "trophy scalp" for a hacking group intending to generate publicity for its grievances with the Indian authorities.
It's hard not to feel sympathy for Symantec - who appear to have been caught in the crossfire between a hacking gang and the Indian authorities.
Although Symantec customers may not be at risk, it's easy to see how the software company will feel bruised by the publicity that the Lords of Dharmaraja have generated through their hack.



Thursday, January 5, 2012

Who Was the First Hacker?

New Scientist has recently revealed the name of the world's first hacker, who managed to discover a security hole in Marconi's wireless telegraph and managed to show the inventor up.
It turned out that a stage magician named Nevil Maskelyn wrecked a public demo of Marconi's wireless telegraph over a century ago, in 1903, – he sent insults in Morse code down the wire. The crowd was really amused when the physicist John Ambrose Fleming has been adjusting arcane apparatus while preparing to show the long-range wireless communication system created by his boss, the Italian radio pioneer Guglielmo Marconi, who was several hundreds miles away trying to send the message.

However, before the show could start, the apparatus in the lecture theater started to tap out a message – it appeared to be a poem accusing Marconi of "diddling the public". Fleming's assistant found out that beaming powerful wireless pulses into the theater were strong enough to be able to interfere with the electric arc discharge lamp of the projector. The apparatus began spelling "Rats" repeatedly and after this ripped into the poem.

That’s how Maskelyn proved that Marconi's item was insecure, and the others could easily eavesdrop on private messages as well. Meanwhile, Fleming fired off a missive to the Times, calling the hack “scientific hooliganism” and asking the readers to help him find the hacker. Nevertheless, Maskelyn, whose family earned money by making "spend-a-penny" locks in pay toilets, outed himself 4 days later. He tried to justify his actions by the security holes it discovered for the public good. He used Morse code in his mind-reading tricks and managed to send wireless messages between a ground station and a balloon located 10 miles away. Nevertherless, Maskelyn was stuffed up by the fact that Marconi had patents on his technology but failed to develop it.

It later appeared that he was hired as a spy for the Eastern Telegraph Company that was worried that Marconi could stuff up its business.

The first hacker built a 50-metre radio mast somewhere on the cliffs in order to find out if he could eavesdrop on messages beamed by Marconi Company to vessels. As a result, Maskelyn pointed out that Marconi’s security was a doddle to hack. Although Maskelyne's name had been forgotten, he is now again in the history books as the world's first hacker.

How to Combine Rescue Disks to Create the Ultimate Windows Repair Disk.

To create the rescue disk, you’re going to want a USB flash drive with a decent amount of space—for our purposes, 2 GB is the minimum size, but you’d be better off with something a little bigger if you want to put a lot of repair disks on it, especially the larger ones.


Once you’ve picked out your drive, the first thing you’ll need to do? Format your drive as FAT32. That’s right, the software we’re going to use requires the FAT32 file system, so right-click on the drive and select Format from the menu.


Choose FAT32 from the drop-down menu under File system, and then click Format.


To create the custom drive, we’ll use a small piece of software called SARDU, which combines a bunch of functionality into a single package—you can use it to download the ISO images, write everything to the USB drive, or create an ISO image that you could burn to an optical disc—though obviously you’re space-limited in that case.

Once you download and extract SARDU, you can simply start clicking on any of the buttons to trigger a download of that rescue disk.
There’s a whole bunch of utilities included, including really useful ones like Gparted and the System Rescue CD, Ophcrack, and others.
And you can use it to directly download Ubuntu as well.
Or you can download the ISO images separately and put them into the ISO folder (you’ll have to restart the application once you’re done).

All done? click the Make a USB button over on the right-hand side…
And everything will be created and copied to the drive.

Just plug the disk into an available port, and choose the option to boot from USB—you may have to take a trip into the BIOS settings to enable booting from removable drives, or you might have to hit a key during bootup to display the boot options menu, where you can choose the device to boot from.

Once you do successfully boot from the flash drive, you’ll see a menu like this:
Select any of the categories, and you’ll see all the rescue disks or other disks that you’ve put on your drive:

Just like that, you’re booting your rescue disk.
Enjoy your awesome rescue disk.

Sunday, January 1, 2012

Facebook hands out White Hat debit cards to hackers.

This is the Visa debit card Facebook is giving to some security researchers for reporting bugs.
A few companies pay money to bug hunters. But Facebook is giving out something more unique than just a check. Some security researchers are getting a customized "White Hat Bug Bounty Program" Visa debit card.
The researchers, who can make thousands of dollars for reporting just one security hole on the social-networking site, can use the card to make purchases, just like a credit card, or create a PIN and take money out of an ATM. As the researchers find more bugs, Facebook can add more money to the account.

Facebook wanted to do something special for the people who are helping the company shore up its software and keep hackers and malware out.
"Researchers who find bugs and security improvements are rare, and we value them and have to find ways to reward them," Ryan McGeehan, manager of Facebook's security response team, told CNET in a recent interview. "Having this exclusive black card is another way to recognize them. They can show up at a conference and show this card and say 'I did special work for Facebook.'"

Besides holding cash value, the White Hat card may proffer other advantages. "We might make it a pass to get into a party," for instance, McGeehan said. "We're trying to be creative."
Facebook launched its bug bounty program in July, following in the steps of Mozilla and Google. The minimum a researcher can make for reporting a bug that is eventually confirmed is $500, and there is no maximum. Researchers have to follow Facebook's Responsible Disclosure Policy and not go public with the vulnerability information until the hole has been fixed.


The most Facebook has paid out for one bug report is $5,000, and it has done that several times, according to McGeehan. Payments have been made to 81 researchers, he said.
Recently, "someone came to us with a bounty-worthy ticket and they said they didn't want the bounty," he said. Instead, the researcher wanted the money--$2,500--to go to a charity and for Facebook to match it. Facebook agreed, McGeehan said.

Brian Krebs, who first wrote about the White Hat Visa, reports that recipients have included Szymon Gruszecki of Poland and Neal Poole, a junior at Brown University who will be an intern at Facebook next summer. 

And Charlie Miller, a researcher at Accuvant better known for finding holes in iOS 5 and Safari than Facebook, also has received a White Hat card. "Facebook whitehat card not as prestigious as the SVC card, but very cool ;) Fun way to implement no more free bugs," he tweeted.
Facebook has plans to leverage the knowledge and skills of the researchers beyond just providing the bug 
 bounty incentive.

"Whenever possible we're going to try to load-in White Hat researchers into products early--as soon as (they are) in production," McGeehan said. Thus Facebook "will get an early warning on anything they find."

Saturday, December 31, 2011

Anonymous targets military-gear site in latest holiday hack.

On Christmas Day the target was security think tank Strategic Forecasting, or Stratfor. This time it was SpecialForces.com, a Web site that sells military gear. 

Specialforces.com
"Continuing the week long celebration of wreaking utter havoc on global financial systems, militaries, and governments, we are announcing our next target: the online piggie supply store SpecialForces.com," the group wrote in a Pastebin posting today. 

The hackers said they breached the SpecialForces.com site months ago, but only just got around to posting the customer data. Even though the site's data was encrypted, they claim to have 14,000 passwords and details for 8,000 credit cards belonging to Special Forces Gear customers. 

Special Forces Gear founder Dave Thomas confirmed that his company's Web servers were compromised by Anonymous in late August, resulting in a security breach that allowed the hackers to obtain customer usernames, passwords, and possibly encrypted credit card information in some cases. "We have no evidence of any further security breaches, and we believe that the recent Stratfor incident is being used to bring this old news back into the spotlight," he noted.


Thomas added that the compromised passwords were from a backup of a previous version of the Web site that is more than a year old. "Most of the credit card numbers are expired, and we don't have evidence of any credit card misuse at this time," he wrote. "The current Web site does not store customer passwords or credit card information."

After the security breach, "we completely rebuilt our Web site and hired third-party consultants to help us shore up Web site security," he said, adding that the vast majority of the sites' sales are custom t-shirts and related gifts, and that the company donates a portion of its profits to charity.


Identity Finder, a New York-based data loss and identity theft prevention service, determined that files posted to date by Anonymous and its AntiSec offshoot related to this breach include 7,277 unique credit card numbers; 68,830 e-mail addresses (of which 40,854 are unique); and 36,368 plain-text usernames and passwords, some of which might be duplicates.
In the statement issued today, the hackers also took another shot at Stratfor for its alleged confusion over whether its data had been encrypted or not.

How Mark Zuckerberg Hacked Into Rival ConnectU In 2004.

ConnectU Founder's
This is the story of how, in the summer of 2004, Mark Zuckerberg hacked into a Facebook rival called ConnectU, whose founders had accused him of stealing their idea to build Facebook.  The details of this story were developed from a broader investigation of the origins of Facebook.  The investigation included interviews with more than a dozen sources over two years, as well as what we believe to be relevant IMs and emails from the period.

During the summer of 2004, Mark Zuckerberg's new social network theFacebook.com was already wildly popular.

After Mark launched it in February, the site dominated the conversation at Harvard all spring.  It reached 250,000 users by the end of August and a million users that fall.

TheFacebook.com was so popular that one thing Mark probably never needed to worry about was competition from the other social network launched at Harvard in 2004, ConnectU, whose founders had accused him of stealing their idea.

ConnectU's founders -- Cameron Winklevoss, Tyler Winklevoss, and Divya Narendra -- had launched the site that spring at 15 schools. But it never gained anywhere close to the critical mass of user adoption that Facebook did. Today, 400 million people visit Facebook each month while ConnectU exists only in the Internet archives.

Nevertheless, during 2004, Mark Zuckerberg still appeared to be obsessed with ConnectU. Specifically, he appears to have hacked into ConnectU's site and made changes to multiple user profiles, including Cameron Winklevoss's.

At one point, Mark appears to have exploited a flaw in ConnectU's account verification process to create a fake Cameron Winklevoss account with a fake Harvard.edu email address.

In this new, fake profile, he listed Cameron's height as 7'4", his hair color as "Ayran Blond," and his eye color as "Sky Blue." He listed Cameron's "language" as "WASP-y."

Next, Mark appears to have logged into the accounts of some ConnectU users and changed their privacy settings to invisible.  The idea here was apparently to make it harder for people to find friends on ConnectU, thus reducing its utility.   Eventually, Mark appears to have gone a step further, deactivating about 20 ConnectU accounts entirely.

Mark appeared to be worried about the risk of his actions, but reasoned that ConnectU's developers wouldn't notice a succession of account deactivations coming from the same IP address. He took comfort that Apache logs didn't reveal that type of activity either. Mark also figured that if ConnectU developers did notice anything, their most natural conclusion would be to think that someone had emailed people convincing them to deactivate their accounts.

It is not clear how Mark accessed these accounts. (In an earlier hack of the email accounts of two Harvard Crimson editors, he used login information stored in Facebook's servers.)  It does appear that he retained access to ConnectU's servers for quite some time.

Hacker who bypassed Facebook security pleads guilty.

A British student has pleaded guilty to charges that he breached security at Facebook earlier his year, despite arguing that his intentions were not malicious.


York computer science student Glenn Steven Mangham, 26, attempted to bypass security on the company's internal systems, raising alarm amongst the FBI that industrial espionage was occurring, according to media reports.

Mangham, who had previously been rewarded by Yahoo for finding vulnerabilities in its systems, discovered that Facebook was far from amused by his activities.

The social networking giant discovered evidence that pointed back to Mangham and he was arrested by the Metropolitan Police Central e-Crime Unit (PCeU) in June.

Specifically, Mangham was accused of using a computer program to secure unauthorized access to Facebook, of attempting to hack into Facebook's Mailman server (used to run internal and external email lists), and attempting to secure access to the Facebook Phabricator server used by internal developers.

Southwark Crown Court was told Mangham produced software scripts that could hack into Facebook's Phabricator server to download "highly sensitive intellectual property".

In addition, the student was said to have breached a webserver used by Facebook to set software development puzzles to programmers who might be interested in working for the company.
Mangham's defence team has argued that he was an "ethical" or "white-hat" hacker, whose intentions - rather than being malicious - were to uncover security vulnerabilities at Facebook with the intention of getting them fixed.


Facebook users will be relieved to hear that the social network told BBC News that the attack "did not involve an attempt to compromise or access user data."

Monday, May 23, 2011

Sony takes sites down after log-in exploit found

The sign-in for PlayStation Network on the Web was out of service this morning.
Just days after most services for PlayStation Network were brought back online, it appears a new exploit has been discovered that allows hackers to change users' passwords with the data stolen during the break-in to the service last month.
The Web sites that allow PSN users to sign in and reset their passwords have since been taken offline, as the graphic above from PlayStation.com shows. This problem reportedly does not affect the ability to sign in via a PlayStation 3 or PlayStation Portable, just some Sony Web sites.
The report comes from gaming blog Nyleveia, which posted a warning to PSN users that their passwords might not be safe and contacted Sony about it.
Another blog, Eurogamer, says it confirmed the exploit, which allows someone to reset your password by knowing your e-mail address used for the account and date of birth. That information is known to be among the data belonging to 100 million users of Sony's gaming services that was exposed between April 17 and 19 in the second-largest security breach in U.S. history.
Eurogamer says users that changed the e-mail address connected to the PSN account after PSN was restored this weekend should not be at risk.
Yesterday, speaking to a handful of reporters, Sony CEO Howard Stringer admitted that while the company had rebuilt the security for PSN during the three weeks it was unavailable, no system could be guaranteed "100 percent secure."
Update 11:12 a.m. PT: Sony spokesman Patrick Seybold wrote today in a blog post that Sony "temporarily took down the PSN and Qriocity password and reset page." There was "no hack," he emphasized, but a "URL exploit that we have subsequently fixed."
At the time of this update, PlayStation.com and Qriocity.com log-in pages were still inaccessible.

Friday, May 20, 2011

Relive the Early Days of the Internet at Telehack



Once upon at time before the age of HTML, the internet looked like a command prompt and a world of text. Telehack is a simulation site that recreates the early internet experience.
How exactly does it recreate the experience? From the Telehack FAQ file:
Telehack is a simulation of a stylized arpanet/usenet, circa 1985-1990. It is a full multi-user simulation, including 25,000 hosts and BBS’s the early net, thousands of files from the era, a collection of adventure and IF games, a working BASIC interpreter with a library of programs to run, simulated historical users, and more.
It’s a well fleshed out project that allows you to use commands, load games, navigate the network, interact with real users (currently logged in) and see significant historical users (simulated for posterity). You can access the project either via web interface or by firing up an actual telnet client and connecting in the old fashioned way. Hit up the link below to access the web portal and type telehack.txt at the prompt to read more about the project.

Sunday, May 15, 2011

Add Copy To / Move To to the Windows Explorer Right Click Menu

A hidden functionality in Windows allows you to right click on a file, select Copy To Folder or Move To Folder, and the move to box will pop up and let you choose a location to either copy or move the file or folder to.

Here’s the quick registry hack to get this working. As usual, back up your registry just in case. You will want to browse down to this key:
HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\ContextMenuHandlers
Once you are at that key, right click and choose the New Key option:

Now you will double-click on the (Default) value and enter the following:
{C2FBB630-2971-11D1-A18C-00C04FD75D13}
Click OK and continue.

If you want to enable Move To, you will repeat the same steps, except creating a new key named Move To, and using this value:
{C2FBB631-2971-11D1-A18C-00C04FD75D13}
Now when you right click on a file or folder, you should see the following options:

Let’s click Copy To Folder just to see what happens….

And that’s it. Useful!

Play Angry Birds in Your Favorite Browser (Web App, Website, and a Game Hack)

Are you ready to indulge in all of that Angry Birds goodness with your favorite browser? Then we have just what you need with information about the web app for Chromium-based browsers, accessing the game via website using your favorite browser, and a quick hack to unlock all of the levels.
First we will start off with the app for Chromium-based browsers. While this is little more than a link to the official website it can be nice to have if you like keeping everything neat and organized in your Apps Tab.

Decided that you want to play Angry Birds in Firefox, Opera, or another browser? Then you can visit the website directly and play the game there! You can choose between the Standardand HD versions as desired…


Want to unlock (or relock) all of the levels when playing Angry Birds in your favorite browser? Then use the following bits of code by pasting them into the Address Bar while the game is open and hit Enter.
Unlock the Levels
javascript: var i = 0; while (i<=69) { localStorage.setItem(‘level_star_’+i,’3′); i++; } window.location.reload();
Lock the Levels
javascript: var i = 0; while (i<=69) { localStorage.setItem(‘level_star_’+i,’-1′); i++; } window.location.reload();



Thursday, May 12, 2011

Don't fall for 'First Exposure: iPhone 5' Facebook scam

Facebook users are being duped into unwittingly spreading spam by clicking on what looks like a link to news entitled "First Exposure: iPhone 5."
A version of the scam, exploiting peoples' interest in the next-generation iPhone, went around Facebook earlier this month, and it's back today with minor changes.
The scam starts when you see someone in your social network comment on a link in a post that looks like it leads to a news story about the iPhone 5 at a Web address of "greatlakesnews.info." Clicking on the link takes you to a different Web page, which provides a captcha window where you're asked to verify a word, ostensibly to prove that you are not an automated bot.
If you see this post on Facebook, don't click on it.
Once you click to verify, a message is posted to your Facebook stream notifying all your friends that you commented on the item and providing them with the bogus iPhone 5 link, in a type of attack known as "clickjacking." Then you're asked to choose from a list of items that then lead to a survey which is really marketing, according to this M86 post.
Clickjacking can be a problem on any Web site, but social networks are particularly susceptible because people share so many links. Facebook's advice to not click on strange links even if they are from friends would cut out many of the legitimate links people share on Facebook.
It's good idea to try to avoid getting news from sources that aren't known news sites. But a big red flag is the captcha window--legitimate sites don't typically make you prove you're human to read a news item.

Wednesday, May 11, 2011

Yankees' error leaks personal data on 21,000 fans


A sales rep for the New York Yankees accidentally e-mailed a spreadsheet containing names, addresses, phone numbers, e-mail addresses, and seat numbers of more than 21,000 season ticket holders to thousands of clients, according to blog site Deadspin.
"There are no credit card numbers, but there are account ID numbers. And on Yankees.com, licensees need only their account ID number and password to access their accounts," the report said yesterday. "With the spreadsheet, we have all the account IDs and can probably guess more than a few passwords via spouse's names, street names, and good old 'abc123.' At the very least, the list email addresses are valuable to spammers."
Later, the Yankees sent an e-mail to season ticket subscribers confirming that a rep had inadvertently included an attachment with ticket holder information to an e-mail that was sent on Monday.
"Please note, immediately upon learning of the accidental attachment of the internal spreadsheet, remedial measures were undertaken so as to assure that a similar incident could not happen again," the e-mail said. "The Yankees deeply regret this incident, and any inconvenience that it might cause."
The mistake puts affected fans at risk of phishing attacks and people should be wary of e-mails or phone calls from people claiming to be affiliated with the Yankees and asking for sensitive information.
The data leak contrasts with other recent breaches that are attributed to hacking attacks or unauthorized access. Sony warned this week of a serious breach on the Sony PlayStation Network that puts data of as many as 77 million customers at risk and potentially includes credit card numbers. Earlier this month, dozens of big name financial companies and retailers were forced to warn customers earlier about the potential for phishing attacks after a breach at e-mail marketing provider Epsilon. And DSLReports.com also had e-mail addresses stolen in an attack on its site this week.

Microsoft plugs critical hole in Windows


Microsoft today fixed a critical hole in Windows and two less serious holes in Office in one of the lightest Patch Tuesdays in recent history.
The critical bulletin, MS11-035, fixes a vulnerability in the Windows Internet Name Service (WINS) that "could allow remote code execution if a user received specially crafted malware on an affected system running the WINS service," according to the bulletin advisory. It affects Windows Server 2003 and 2008.
WINS is not installed on the affected operating system software by default, so only customers who manually install it are affected and will be offered the update, Microsoft said.
"Microsoft is downplaying the bug, but there is potential here for remote code execution," and thus total control of the computer, said Andrew Storms, director of security operations at nCircle. "WINS is a network-aware application that does not require authentication, and many enterprises require WINS on their networks. Taken together, these factors mean that a lot of enterprises will find their internal network servers vulnerable to a remote code bug. Initially, most attackers will probably only trigger a DoS (denial-of-service) event, but finding the remote code exploit won't be far behind."
The second bulletin, MS11-036, fixes two vulnerabilities in Microsoft PowerPoint that could allow remote code execution if a user opens a malicious PowerPoint file. The vulnerabilities affect Office XP, Office 2003, Office 2007, Office 2004 for Mac, and Office 2008 for Mac.
Microsoft also changed its Exploitability Index, the guide it uses to provide customers information on how likely a vulnerability is of being exploited. The company will be publishing two ratings per vulnerability, one for the most recent platform and a second as an aggregate rating for all older versions of the software.
Patch Tuesday has been fairly hectic recently, including last month when 17 bulletins were released to fix 64 vulnerabilities

French researchers demo attack on Chrome


French security firm Vupen said today its team has figured out a way to bypass security measures in Chrome and offers a video demo it says is a successful attack against the browser running on a Windows machine.
"We are (un)happy to announce that we have officially Pwnd Google Chrome and its sandbox," the Vupen Security blog said. "The exploit shown in this video is one of the most sophisticated codes we have seen and created so far as it bypasses all security features including ASLR [Address Space Layout Randomization]/DEP [Data Execution Prevention]/Sandbox, it is silent [no crash after executing the payload], it relies on undisclosed (0day) vulnerabilities discovered by VUPEN and it works on all Windows systems (32-bit and x64)."
In the video, someone using Chrome v11.0.696.65 on Windows 7 Service Pack 1 (x64) is tricked into visiting a malicious Web page hosting the exploit. Once the machine is compromised, the exploit code downloads a Calculator program from a remote location and launches it outside the sandbox at "medium" integrity level, according to Vupen.
"While Chrome has one of the most secure sandboxes and has always survived the Pwn2Own contest during the last three years, we have now uncovered a reliable way to execute arbitrary code on any installation of Chrome despite its sandbox, ASLR and DEP," the post said.
Vupen, which did not respond to an e-mail seeking comment today, said it would not publicly disclose the exploit code or technical details of the vulnerabilities but will share them with its government customers as part of its vulnerability research services.
Asked for comment, a Google spokesman said: "We're unable to verify VUPEN's claims at this time as we have not received any details from them. Should any modifications become necessary, users will be automatically updated to the latest version of Chrome."
Chrome's sandbox technology is designed to isolate code from other parts of the computer so that if malicious code does get in, its damage is limited. Adobe has added sandbox technology to Reader.

Facebook plugs third-party access to user accounts


Tokens are like "spare keys" that Facebook users grant to applications that allow them to perform actions on their behalf or access their profile


Facebook has plugged a hole that was inadvertently providing advertisers and other third parties access to user accounts via tokens that serve as "spare keys," Symantec said today after disclosing the problem to the social-networking company.
"Facebook was notified of this issue and has confirmed this leakage," Nishant Doshi, a senior software engineer at Symantec, wrote in a blog post. "Facebook notified us of changes on their end to prevent these tokens from getting leaked."
"We estimate that as of April 2011 close to 100,000 applications were enabling this leakage," Doshi wrote. "We estimate that over the years, hundreds of thousands of applications may have inadvertently leaked millions of access tokens to third parties."
A Facebook spokesperson told CNET that the company could not find any evidence that private user information was being shared with unauthorized third parties and that contractual obligations prohibit advertisers and developers from obtaining or sharing user information in a way that violates the site's policies.
"We have no evidence of this information being used in a way that violated our policies, but nonetheless, we take any potential issue seriously and quickly took steps to prevent this from happening with apps on Facebook," a company statement said.
User access tokens, which are akin to "spare keys," allow applications to perform certain actions on behalf of the user or to access the user's profile, according to Doshi. Most tokens expire after a short time, but the application can request offline access tokens, which allow them access until the user changes the password, even when the user is not logged in, according to his post.
The leak was happening when an application used a legacy Facebook application programming interface with older authentication schemes, instead of the new OAuth 2.0 data sharing protocol, Doshi said. (Google began supporting OAuth in mid-2008.) If certain parameters were used in the coding, the tokens would be sent in a URL to the application host, and from there could be leaked to advertisers and analytic platforms via iFrame applications embedded in the page, he said.
Its unclear how many people are affected by this problem.
"There is no good way to estimate how many access tokens have already been leaked since the release Facebook applications back in 2007," Doshi wrote. "We fear a lot of these tokens might still be available in log files of third-party servers or still being actively used by advertisers."
Facebook users can change their passwords to invalidate any leaked access tokens, effectively changing the lock on your profile, he said.
The Symantec research prompted Facebook to make some changes in its developer road map, including requiring all sites and apps to migrate to OAuth 2.0 and obtain an SSL (secure sockets layer) certificate by October 1.
"We have been working with Symantec to identify issues in our authenticationflow to ensure that they are more secure," the company said in a post on its developer blog. "This has led us to conclude that migrating to OAuth & HTTPS (Hypertext Transfer Protocol Secure) now is in the best interest of our users and developers."
Joey Tyson, a security engineer at Gemini Security Solutions who blogs about social networking at TheHarmonyGuy.com, said Facebook has been progressively improving the security of its platform and that many apps have limited permissions now. "This is a problem worth addressing, but it may not be as serious as some people are thinking it is, and it's certainly not as widely exploited as some people may fear," he sai