Budget Express 2026

co-presented by

  • JIO BlackRock

ASSOCIATE SPONSORS

  • Sunteck
  • SBI
HomeNewsTechnologyHacker finds Facebook flaw that exposes private information

Hacker finds Facebook flaw that exposes private information

Facebook has found itself engulfed in yet another hacking scandal, only this time, its scarier than a simple malware problem. A hacker has been able to...

February 26, 2013 / 18:10 IST

Facebook has found itself engulfed in yet another hacking scandal, only this time, it’s scarier than a simple malware problem. A hacker has been able to exploit a major privacy flaw in the social networking giant’s OAuth permissions to access almost anyone’s private data. Security hacker Nir Goldshlager described his exploits in a blog post, detailing how he went about working through a flaw in the website. The OAuth permission crops up every time an application needs some or all of your information to run smoothly on Facebook. When you hit the ‘Allow’ button on the site, the application gets access to information like your name, your age, your location and more. The app can even seek permission to post on your timeline on your behalf.“I found a way in to get a full permissions (read inbox, outbox, manage pages, manage ads, read private photos, videos,etc..) over the victim account even without any installed apps on the victim's account,” Goldshlager revealed. “By exploiting this flaw I could steal unique access tokens that provides me full control over any Facebook account,” he wrote.

Click here for full story

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

first published: Feb 26, 2013 06:00 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347