Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

11/21/2011
01:37 PM
50%
50%

7 Facebook Security Problems Linger

Social networking giant might have fixed its porn problem, but it has plenty of other issues to reckon with, experts say.

Facebook has largely erased the rash of porn and violent images that affected the site last week, but its problems are far from over, researchers said yesterday.

In a blog about Facebook's security vulnerabilities posted Thursday, researchers at security vendor Barracuda Networks said Facebook still has little incentive to improve its site security.

"When you are trying to grow a social network as well as increase advertising revenue, security becomes not only a lower priority but sometimes a conflict of interest," the blog states.

Facebook continues to miss some key security issues on its pages, Barracuda says, and it outlined seven:

1. Fake Product Pages. "Knock-off luxury goods have always been popular scams," the blog noted. "If you actually get the product, which is a bit of a longshot, you are likely to find that the quality you expected from the brand is lacking at best. Facebook is rife with pages promoting these goods."

2. Manipulated Accounts Recommendations. "On social networks, those with less good motives have figured out how to game the recommendation system and use it to their advantage," the blog says. "This is very similar to how attackers have used search engine optimization to promote their malware. Friends are recommended in a variety of ways, but a simply exploited example is through shared apps. Spammer accounts sign up for the same popular apps that real users do and before too long they are showing up in your list of recommended friends."

3. Affiliate Spam. "Affiliate spam is a bigger and bigger part of the typical users incoming stream," Barracuda states. "They encourage or require the user to share it out to all their friends and say something like 'I love Olive Garden' before being redirected to a never-ending series of offers."

Read the rest of this article on Dark Reading.

InformationWeek is conducting a survey on the current state of encryption within the enterprise: What assets are, and are not, being encrypted to reduce the risk of exposure? Where sensitive data is going unencrypted, what's holding you back? Upon completion, you will be eligible to enter a drawing to receive an Apple 32-GB iPod Touch. Take the survey now. Survey ends Dec. 2.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Oscar Branson
50%
50%
Oscar Branson,
User Rank: Apprentice
4/30/2013 | 6:17:13 AM
re: 7 Facebook Security Problems Linger
facebook has many graphic violent videos posted all the time, fact is i have reported numerous graphic videos that depict women being murdered * having hheads cut off with a knife) Facebook has never removed these videos as graphic violent videos do not infringe on Facebooks graphic violence policy. Facebook is becoming a dismal failure
Deb Donston-Miller
50%
50%
Deb Donston-Miller,
User Rank: Apprentice
11/28/2011 | 5:51:02 PM
re: 7 Facebook Security Problems Linger
I think social networking complicates things a bit more than we've seen with traditional online activity. People have to be more on guard because of more frequent changes and the wealth of information that can be used against you in a phishing attack. But I agree in principle that users need to approach Facebook and any online site with caution and armed with knowledge.

Deb Donston-Miller
Contributing Editor, The BrainYard
US Turning Up the Heat on North Korea's Cyber Threat Operations
Jai Vijayan, Contributing Writer,  9/16/2019
MITRE Releases 2019 List of Top 25 Software Weaknesses
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2019
7 Ways VPNs Can Turn from Ally to Threat
Curtis Franklin Jr., Senior Editor at Dark Reading,  9/21/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-16695
PUBLISHED: 2019-09-22
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.
CVE-2019-16696
PUBLISHED: 2019-09-22
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.
CVE-2018-21018
PUBLISHED: 2019-09-22
Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.
CVE-2019-16692
PUBLISHED: 2019-09-22
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
CVE-2019-16693
PUBLISHED: 2019-09-22
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.