Facebook and Twitter User accounts hacked with offers of fee i-pads
September 7th, 2010 by Geoff
A spammer has managed to successfully hack into Facebook’s photo upload system in order to spam Facebook and Twitter with photos promising free iPads and iPhones.
The spammer who managed to post these photos to people’s walls, exploited a flaw in the system which did not check if a photo could be posted to someone’s profile and pretend to be from that person, then send this photo promoting schemes of free or cheap gadgets.
People who saw these photos appear on their wall assumed it was just their account that had been hacked and then change their password. However, this didn’t make any difference as the flaw is in the photo authentication code in Facebook.
Facebook commented that they had found a bug in the code that processes the photos when they are being uploaded. The bug caused a block in the checks that are normally made as to whether the photo should be posted to a person’s profile. While fixing the problem the spammer managed to post photos to people’s profiles that they hadn’t approved.
This spammer made the most of weak passwords. The photos and message were sent via web so it didn’t look like a third person or a linked site had sent the messages.
Link to us
If you want to link to this blog, copy and paste the following HTML code to your website.









