Spanish brickie finds Facebook hacking flaw

Nov 30, 2011
A Spanish builder stumbled on an online loophole that enables users to send Facebook messages in other users' names, prompting an alert by authorities, he said Wednesday.

A Spanish builder stumbled on an online loophole that enables users to send Facebook messages in other users' names, prompting an alert by authorities, he said Wednesday.

Spain's said it had alerted the US online networking site after Alfredo Arias, 37, warned them of the that allows a hacker to use e-mail addresses when sending spoof messages.

Arias found that anyone who knows how to create an online messaging form -- a simple procedure for a website designer -- can enter another person's e-mail address in the "sender" field and send a message as if it were from them.

The procedure is a common trick of online frauds, but Spain's government Internet watchdog Inteco said it was concerned to see that Facebook's e-mail service did not have safeguards to stop its addresses being misused this way.

"It is very easy. You only have to know how to create a web page to do it," Arias, from the northern Spanish city of Leon, told AFP.

He said he alerted the institute and published details of how to carry out the procedure on his blog.

Inteco issued a warning to about the risk.

"We issued this message when we heard of this concrete case," a spokeswoman for the institute told AFP, adding that it had alerted Facebook.

"While the problem is common to all e-mail services, on Facebook it takes on a bigger dimension by linking in to the online ," said a warning to web users published by Inteco's Bureau.

"This flaw could be used by ill-intentioned users for example to pass themselves off as a friend of the victim and invite them to visit malicious web pages or download untrustworthy applications."

Separately, US authorities said Tuesday that Facebook agreed to tighten its privacy policies and submit to external audits in order to settle charges that it abused users' personal data.

That deal settled two-year-old accusations that Facebook -- which has some 800 million users -- had allowed advertisers access to users' personal data when users were told it was being kept private.

Explore further: Google asks US secret court to lift gag order (Update)

add to favorites email to friend print save as pdf

Related Stories

Privacy groups ask FTC to investigate Facebook

Sep 29, 2011

(AP) -- Nine privacy groups have sent a joint letter to the Federal Trade Commission saying it should investigate the ways Facebook collects data about users' online activity after recent changes to its site.

Facebook glitch exposes chat messages (Update 2)

May 05, 2010

Facebook on Wednesday temporarily shut down its online chat feature after a software glitch let people's friends in the online community see each others' private chat messages.

Facebook reaches German privacy deal

Jan 24, 2011

(AP) -- Facebook said Monday it has reached a deal with German data protection officials in a dispute over unsolicited invitations sent to non-members of the social networking site through its "Friend Finder" feature.

Recommended for you

Google asks US secret court to lift gag order (Update)

11 hours ago

Google on Tuesday sharply challenged the U.S. government's gag order on its Internet surveillance program, citing what it described as a constitutional free speech right to divulge how many requests it receives ...

Mysterious Facebook event sparks online buzz

Jun 17, 2013

A mysterious Facebook event set for Thursday has sparked buzz that the leading social network could be adding video to Instagram smartphone picture-sharing service.

Report of British hacking raises hackles abroad

Jun 17, 2013

A newspaper report that British eavesdropping agency GCHQ repeatedly hacked into foreign diplomats' phones and emails has prompted an angry response from traditional rival Russia and provoked demands for ...

Explainer: What is a virtual private network (VPN)?

Jun 17, 2013

Have you ever wanted to exist in more than one place at the same time? The laws of physics suggest wormholes through space and time are hypothetical; but wormholes do exist in cyberspace and wonders can be ...

Report: UK spies hacked foreign diplomats

Jun 17, 2013

The Guardian newspaper says the British eavesdropping agency GCHQ repeatedly hacked into foreign diplomats' phones and emails when the U.K. hosted international conferences, even going so far as to set up ...

User comments : 0

More news stories

Mozilla lab wants scientists to step out of analog age

(Phys.org) —Talk about big ideas. Not satisfied to rest on laurels of having brought forth the open source browser Firefox, Mozilla—defined by some as a global project, by others as one of the key open-source ...

3D printing tiny batteries

(Phys.org) —3D printing can now be used to print lithium-ion microbatteries the size of a grain of sand. The printed microbatteries could supply electricity to tiny devices in fields from medicine to communications, ...