We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
 
74,953 News Articles

Facebook fixes bug that allowed friend deletion

Bug was a variation of an earlier vulnerability

Facebook has fixed a flaw that let hackers delete Facebook friends without permission.

The flaw was reported last week by Steven Abbagnaro, a student at Marist College in Poughkeepsie, New York. It was patched on Friday  after the IDG News Service notified Facebook of the issue.

The bug was a variation of an earlier vulnerability that Facebook learned about earlier this month, which affected a range of features on the website. Hackers could have leveraged Abbagnaro's bug to delete all of a victim's contacts, one by one, but it does not appear that anyone ever exploited it in a malicious way.

For Abbagnaro's attack to work, however, a user would have to have been tricked into clicking on a malicious web link while still logged into Facebook.

Facebook has struggled to fix these bugs, which are called cross-site request forgery flaws. They exist because of relatively simple web programming mistakes in the website's code, and security researchers have criticised Facebook for not fixing them more quickly.

"We're in the process of doing a full audit and are building additional protections for this type of potential attack across the code base," said Simon Axten, a Facebook spokesman, on Friday. "We began working on this one as soon as we learned about it and pushed a fix early this afternoon."

See also:

PC security advice


IDG UK Sites

Amazon 3D smartphone release date, price and spec: The hologram phone?

IDG UK Sites

You're never alone with a clone: How the App Store got taken over by copycats

IDG UK Sites

PCs vs consoles: PCs still pwn when it comes to gaming (and everything else)

IDG UK Sites

The art of rebranding: Creative agency The Neighbourhood explains how & why it rebranded