Vulnerabilities / Threats
11/21/2011
01:37 PM
50%
50%

7 Facebook Security Problems Linger

Social networking giant might have fixed its porn problem, but it has plenty of other issues to reckon with, experts say.

Facebook has largely erased the rash of porn and violent images that affected the site last week, but its problems are far from over, researchers said yesterday.

In a blog about Facebook's security vulnerabilities posted Thursday, researchers at security vendor Barracuda Networks said Facebook still has little incentive to improve its site security.

"When you are trying to grow a social network as well as increase advertising revenue, security becomes not only a lower priority but sometimes a conflict of interest," the blog states.

Facebook continues to miss some key security issues on its pages, Barracuda says, and it outlined seven:

1. Fake Product Pages. "Knock-off luxury goods have always been popular scams," the blog noted. "If you actually get the product, which is a bit of a longshot, you are likely to find that the quality you expected from the brand is lacking at best. Facebook is rife with pages promoting these goods."

2. Manipulated Accounts Recommendations. "On social networks, those with less good motives have figured out how to game the recommendation system and use it to their advantage," the blog says. "This is very similar to how attackers have used search engine optimization to promote their malware. Friends are recommended in a variety of ways, but a simply exploited example is through shared apps. Spammer accounts sign up for the same popular apps that real users do and before too long they are showing up in your list of recommended friends."

3. Affiliate Spam. "Affiliate spam is a bigger and bigger part of the typical users incoming stream," Barracuda states. "They encourage or require the user to share it out to all their friends and say something like 'I love Olive Garden' before being redirected to a never-ending series of offers."

Read the rest of this article on Dark Reading.

InformationWeek is conducting a survey on the current state of encryption within the enterprise: What assets are, and are not, being encrypted to reduce the risk of exposure? Where sensitive data is going unencrypted, what's holding you back? Upon completion, you will be eligible to enter a drawing to receive an Apple 32-GB iPod Touch. Take the survey now. Survey ends Dec. 2.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Oscar Branson
50%
50%
Oscar Branson,
User Rank: Apprentice
4/30/2013 | 6:17:13 AM
re: 7 Facebook Security Problems Linger
facebook has many graphic violent videos posted all the time, fact is i have reported numerous graphic videos that depict women being murdered * having hheads cut off with a knife) Facebook has never removed these videos as graphic violent videos do not infringe on Facebooks graphic violence policy. Facebook is becoming a dismal failure
Deb Donston-Miller
50%
50%
Deb Donston-Miller,
User Rank: Apprentice
11/28/2011 | 5:51:02 PM
re: 7 Facebook Security Problems Linger
I think social networking complicates things a bit more than we've seen with traditional online activity. People have to be more on guard because of more frequent changes and the wealth of information that can be used against you in a phishing attack. But I agree in principle that users need to approach Facebook and any online site with caution and armed with knowledge.

Deb Donston-Miller
Contributing Editor, The BrainYard
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.