republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Amateur Programming Error Exposes Facebook Code
Uniqs:
236
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Analysis of an Ecard Exploit Page »
« UN website targeted by hackers  

Sindows 7

join:2006-09-13
Hope, BC

Amateur Programming Error Exposes Facebook Code

»blog.wired.com/monkeybites/2007/···ram.html

Owing to a misconfigured server, Facebook exposed its homepage code to what the company called “a handful of users” over the weekend. The leaked code was promptly posted on a new blog, Facebook Secrets, for all of the internet to see.

Although Facebook hasn’t specified what exactly was wrong with the server, it seem reasonable to conclude that some sort of mod_php error caused apache to serve the code as an ordinary text file rather than processing it as PHP.

The code leak does not constitute a security breach and there’s probably no immediate reason to be concerned about your data. However, given the number of PHP includes and auxiliary file paths listed, hackers now have a much better idea of how Facebook works and where potential vulnerabilities may lie. And it’s hardly comforting that such an amateur programming mistake is happening to a site the size Facebook.

PHP is notorious for just this sort of thing — serving code as text — but there are ways you prevent it from happening on your own site. The easiest and most effective way is to use the Apache module mod_security, which can detect and stop PHP source code from being sent at plain text.

Regrettably for Facebook, the site apparently wasn’t using mod_security on the particular server that was misconfigured.

One group that should be quite happy with the leak is ConnectU, the company currently embroiled in a lawsuit with Facebook which alleges that the latter stole code from the former. If the alleged code happened to be on Facebook’s front page, ConnectU’s case just got a whole lot stronger, though ConnectU hasn’t said anything to that effect.

Given the amount of personal data that many people have dumped into Facebook, an outside security breach would likely lead to an identity theft nightmare, should it ever happen. And if this weekend’s code leak is any indication, Facebook doesn’t seem to be operating at the security level you would expect from a site of that size
Forums » Up and Running » Security » SecurityAnalysis of an Ecard Exploit Page »
« UN website targeted by hackers  


Monday, 14-Dec 18:41:26 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [102] Google To Sell Phone Directly To Consumers
· [96] Verizon Kindly Forgives Kid's $21,917 3G Bandwidth Bill
· [64] TiVO Tries To Figure Out Where It Fits
· [51] Faster Verizon DSL Service Will Burn Your House Down
· [42] NY Times: AT&T 3G Network Is Secretly Awesome
· [22] Rural Broadband User? You're Screwed
· [21] Sweden First To Get LTE Service
· [16] Can Satire Take Down AT&T's 3G Network?
· [1] Monday Morning Links
Most people now reading
· Official Mediacom Email Discussion Thread [Mediacom]
· Ashen Verdict Rep farming guide (ICC 10) [World of Warcraft]
· [Rant] BUG in MY FOOD, After i ate 90% of it.. [Rants, Raves, and Praise]
· DKs and their obsession with Agility [World of Warcraft]
· personal check etiquette [General Questions]
· how to get money back when ripped off [General Questions]
· Windows 7 boot manager editing questions [Microsoft Help]
· Exalted with Ashen Verdict before the end of the week [World of Warcraft]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Most Hated 5-man now. [World of Warcraft]