Games | Software 
Search

Home|Channels|Hot news|Most visited|Highest rated|
Technology index
Hardware
Interviews
IT Companies
Security
Tech Weblogs
Technology
Set this page as your
home page
Add this page to your
favorites

Home Technology SlashDot IT

Facebook and MySpace Backdoors Found, Fixed
November 5, 2009, 7:00 pm


jamie writes with news of a Facebook app developer who found a significant security hole while he was trying to get around function limitations for his application. Quoting: "Luckily — just with browser AJAX requests — a flash application hosted on domain X is unable to open a file on domain Y. If this would be possible, domain X [would be] able to access content on domain Y, and when the user is logged in on domain Y retrieve and post back any personal data. In certain cases this could limit a Flash application's capabilities. ... To resolve such issues, Adobe (Flash's developers) introduced a 'crossdomain.xml' file which could allow certain domains to access another domain, leading to cross-domain access by certain or all domains. While indeed Facebook locked the front door from any non-Facebook domain access via Flash, a simple subdomain change allowed any flash application (domain="*") to access its domain data." He found a similar problem in MySpace's crossdomain.xml. Both sites were notified, and they have implemented fixes.

Read more of this story at Slashdot.


Read more...
E-mailE-mail  Printer friendlyPrinter friendly version


Rate this article: 1 2 3 4 5  

Related stories...
Tech Lobbyist Named to DHS Top Security Post
Zero-Day IE Exploit In the Wild
Top Five Causes of Data Compromise
Pipeline Worm Floods AIM With Botnet Drones
Hotel Minibar Key Opens Diebold Voting Machines
The Engine of US Jobs
Draft Scheme Standard R6RS Released
CryptoDox: Encyclopedia on Cryptography & Info
Analyzing 20,000 MySpace Passwords
Code Posted For New IE Exploit
Powered by Apache, PHP, MySQL © 2006 Elerion, ltd.