Monday, January 7, 2013

Facebook Bug #4: Password Reset Vulnerability Found in www.facebook.com

Description
Sow Ching Shiong, an independent vulnerability researcher has discovered a Password Reset vulnerability in www.facebook.com, which can be exploited by an attacker to bypass certain security restrictions.

In normal circumstances, an authenticated Facebook user is required to enter his/her current password on the change password page to prevent an unauthorized person from changing the password without the user's knowledge.

However, an attacker can change/reset a user's password without knowing the user's current password by accessing this URL directly: https://www.facebook.com/hacked.
After that, the page will be redirected to https://www.facebook.com/checkpoint/checkpointme?f=[userid]&r=web_hacked
Now, the attacker can click "Continue" to change/reset the user's password.

Proof of concept
Step 1: Logon to Facebook and access this URL directly: https://www.facebook.com/hacked. The page will be redirected to https://www.facebook.com/checkpoint/checkpointme?f=[userid]&r=web_hacked


Step 2: Click on "Continue" to proceed


Step 3: Enter "New Password" and "Confirm Password" to change/reset the password.


Conclusion
This vulnerability has been confirmed and patched by Facebook Security Team. I would like to thank them for their quick response to my report.

Facebook White Hat

https://www.facebook.com/whitehat

26 comments:

  1. That's a nice find Sow. Contrats \m/
    b0nd

    ReplyDelete
  2. Replies
    1. pls hack this account
      http://www.facebook.com/subair.nmlp

      Delete
  3. Facebook Security Team. I would like to thank them for their quick response to my report. get1000fans.com

    ReplyDelete
  4. Replies
    1. Hi, this bug has been fixed by Facebook Security Team.

      Delete
  5. Replies
    1. Hi, this bug has been fixed by Facebook Security Team.

      Delete
  6. You idiot. You coulda become a millionaire in so many ways from this instead of reporting it.

    ReplyDelete
    Replies
    1. Because of guys like you, people are provoked to make crimes. Stop Shortcuts, start helping.

      Delete
  7. Does anyone could help me to find a way or how to hack the password from a facebook user? I need to get inside to the account because this person its sick and its really important the information for our family... I believed that facebook support team will erase or suspend the account if you report them a healthy problem from a user....... Please Please email me (guzmanoctavio@hotmail.com/octguzman@gmail.com) if you can help!! Its just matter of a couple of inbox conversations we need to check...... THANK YOU !!!!

    ReplyDelete
  8. help me to Hack facebook yahoo gmail accounts
    mail me
    khaliqdad91@yahoo.com

    ReplyDelete
  9. Fuck you. Why do you get to find such an easy vulnerability and report it for little money? I was on a similar page in the past. I should've found out about this long ago. Instead I do tons of research on facebook and find nothing as serious as a remote password reset vuln. Moron.

    You coulda stolen tons of large fanpages with that exploit and sold them for thousands or as traffic.

    ReplyDelete
  10. Most of your vulnerability discoveries, haven't been as serious as this one.

    ReplyDelete
  11. great! congratz
    http://www.thehackerspost.com/2013/01/facebook-password-reset-vulnerability.html

    ReplyDelete
  12. Hello
    Dear, I Visit the site.& like your site. I welcome My site.Please visit & comment.
    Facebook New

    ReplyDelete
  13. Which can be exploited by an attacker Steal Facebook Passwords to bypass certain security restrictions.

    ReplyDelete
  14. Home Wellbeing has a wide range of One Stop Home Essentials products that care for the wellbeing of You and Your Loved Ones.

    ReplyDelete
  15. This matter is down to earth, hats off buds out there.
    how to get facebook likes

    ReplyDelete
  16. Home Lifestyle has a wide range of One Stop Home Essentials products suited for the Active, Busy, Mobile and City Living People, bringing the Quality of Life to a different level.

    ReplyDelete