Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

10/28/2010
01:25 PM
50%
50%

Social Networks' Threat To Security

Weak passwords and insecure personal information could put your company's data at risk.

Social networks are designed to facilitate sharing of personal information, and the more data a person discloses, the more valuable he or she is to the service. Unfortunately, these sites have poor track records for security controls. They don't encourage users to select strong passwords, and passwords on these sites never expire. This wouldn't be a problem if people only used these passwords for their social lives, but it's a safe bet that many reuse the same weak passwords--or versions of them--for all of their accounts, including at work.

A database breach last year at RockYou, which creates apps and games for social networking sites, illustrates just how weak passwords can be. Attackers used a SQL injection vulnerability to steal 32 million passwords that were stored in clear text and then posted them to the Internet. This large data set gave us unprecedented insight into the passwords that users select and allowed security researchers to calculate the most common ones (see box on next page).

Attackers often simply try the top 20 passwords when attempting to break into a social network account. Yes, it's a simple dictionary brute-force attack, but if you have a large user base, it's likely at least one of your employees' accounts could be hacked using this method.

Attacker Modus Operandi

Attackers have a variety of ways to guess passwords, including:

>> Brute force based on publicly disclosed information. Beyond the RockYou top 20, people often use names of family members, birthdays, and other personal but easily accessible information in their passwords. Attackers may take what they know about a potential victim and feed it into a program that generates a range of possible passwords.

>> Guessing answers to password-reset questions. Social network users sometimes reveal information that could be used to reset their passwords on the social network itself, Web mail services such as Yahoo Mail, and even on online banking or software-as-a-service sites. For example, some Facebook users include "25 Random Things About You" notes in their profiles. These notes contain information--like mother's maiden name, place of birth, color of a first car--that attackers can use to reset a victim's password and get control of that person's e-mail account.

>> Create a word list to narrow down keywords mentioned in the profile. Several tools can collect keywords from a Web page and put them into a word list (see Easy-To-Find Brute-Force Tools). Once an attacker has this list, he can attempt to brute force the user's password. This attack's effectiveness is largely dependent on how accurate a word list is and whether the social network employs any brute-force prevention mechanisms, such as Captchas, those challenge-response tests used on Web forms to ensure the respondent is a person, not a computer.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-10696
PUBLISHED: 2020-03-31
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
CVE-2020-5344
PUBLISHED: 2020-03-31
Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially cr...
CVE-2020-5292
PUBLISHED: 2020-03-31
Leantime before versions 2.0.15 and 2.1-beta3 has a SQL Injection vulnerability. The impact is high. Malicious users/attackers can execute arbitrary SQL queries negatively affecting the confidentiality, integrity, and availability of the site. Attackers can exfiltrate data like the users' and admini...
CVE-2020-7009
PUBLISHED: 2020-03-31
Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.
CVE-2019-13495
PUBLISHED: 2020-03-31
In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenticated users to inject arbitrary web script via an rpSys.html Name or Location field.