Facebook URL redirection vulnerability patched

Share this article:

A Facebook URL redirection vulnerability discovered last week was patched just a day after a blog post detailing the bug went live.

According to the post by security researcher Dan Melamed, the vulnerability would allow anyone to have a facebook.com link redirect to a website of their choosing “without any restrictions,” simply by removing the “http://” tagged to the end of the URL.

Facebook contacted the researcher to notify him that any suspicious redirects would be caught by their internal Link Shim security tool. However, Melamed, who included a video highlighting the flaw in his post, wrote that “not all malware/spam” could be caught by Facebook, adding that attackers could easily keep shifting to other malicious links.

Discovering the bug is worth $1,000, according to Melamed.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

Florida Supreme Court rules warrants a must for real-time cell location tracking

Florida Supreme Court rules warrants a must for ...

The Florida Supreme Court put the kibosh on warrantless real-time tracking using location data obtained from cell phone providers.

Modular malware for OS X includes backdoor, keylogger components

Modular malware for OS X includes backdoor, keylogger ...

The modular malware was named "Ventir," by researchers at Kaspersky.

Fake Dropbox login page nabs credentials, is hosted on Dropbox

Fake Dropbox login page nabs credentials, is hosted ...

Symantec researchers received a phishing email linking recipients to a fake Dropbox login page that is hosted on Dropbox's user content domain and served over SSL.