When using the Facebook ‘Messages’ tab, there is a feature to attach a file. Using this feature normally, the site won’t allow a user to attach an executable file. A bug was discovered to subvert this security mechanisms. Note, you do NOT have to be friends with the user to send them a message with an attachment.
Description:
When attaching an executable file, Facebook will return an error message stating:
“Error Uploading: You cannot attach files of that type.”
Content-Disposition: form-data; name=”attachment”; filename=”cmd.exe”
It was discovered the variable ‘filename’ was being parsed to determine if the file type is allowed or not.
To subvert the security mechanisms to allow an .exe file type, we modified the POST request by appending a space to our filename variable like so:
filename=”cmd.exe ”
Potentially allow an attacker to compromise a victim’s computer system.
Affected Products:
www.facebook.com
Time Table:
09/30/2011 Reported Vulnerability to the Vendor
10/26/2011 Vendor Acknowledged Vulnerability
10/27/2011 Publicly Disclosed
No comments:
Post a Comment