Facebook URL redirection vulnerability patched

Share this article:

A Facebook URL redirection vulnerability discovered last week was patched just a day after a blog post detailing the bug went live.

According to the post by security researcher Dan Melamed, the vulnerability would allow anyone to have a facebook.com link redirect to a website of their choosing “without any restrictions,” simply by removing the “http://” tagged to the end of the URL.

Facebook contacted the researcher to notify him that any suspicious redirects would be caught by their internal Link Shim security tool. However, Melamed, who included a video highlighting the flaw in his post, wrote that “not all malware/spam” could be caught by Facebook, adding that attackers could easily keep shifting to other malicious links.

Discovering the bug is worth $1,000, according to Melamed.

Share this article:

Sign up to our newsletters

More in News

Brazilian president signs internet 'Bill of Rights' into law

Brazilian president signs internet 'Bill of Rights' into ...

President Dilma Rousseff signed the legislation on Wednesday at the NetMundial conference in Sao Paulo.

Android trojan sends premium SMS messages, targets U.S. users for first time

Android trojan sends premium SMS messages, targets U.S. ...

An SMS trojan for Android, known as FakeInst, has been observed sending premium SMS messages to users all over the world, including, for the first time, the United States.

Report: DDoS up in Q4 2013, vulnerability scanners leveraged to exploit sites

Report: DDoS up in Q4 2013, vulnerability scanners ...

Researchers observed 346 DDoS attacks in the final quarter of 2013 and attackers used Vega and Skipfish vulnerability scanners to exploit web flaws at financial companies.