Google Search

Showing posts with label closes. Show all posts
Showing posts with label closes. Show all posts

Wednesday, December 11, 2013

LinkedIn closes OAuth hole that could have let people tinker with your CV

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

CV and mouse. Image courtesy of ShutterstockLinkedIn has closed a bit of a hole that could have let anyone swipe users' OAuth private login tokens.

OAuth, an open authorization standard, is used by social networking services such as Klout or Foursquare.

OAuth enables users to log in to such services by first signing in to the big social networks, such as Facebook and Twitter.

A software developer identified by The Register as Richard Mitchell, based in the UK, earlier this week blogged about discovering that LinkedIn's help site handed out private OAuth tokens for logged-in users.

These supposedly secret OAuth tokens can be used to impersonate LinkedIn users and potentially get at their profile information via APIs.

Mitchell noted that during authentication, when first loading the page, a request went out to a JavaScript file that included the API key for the help system, which "immediately" returned an OAuth token for the user.

In fact, all that the help desk JavaScript code was doing before handing over the token was checking that the last page the visitor went to was served from LinkedIn.com.

Unfortunately (or fortunately, if you're talking about maintaining your privacy or testing code), "referer spoofing" is a trivial thing for coders.

Somebody with malicious intent could log into LinkedIn and then hop over to a malicious page that's designed to poke the LinkedIn help site for somebody's OAuth token, The Register's John Leyden suggests.

CV. Image courtesy of ShutterstockMalware could also potentially access profile information using APIs, Leyden adds.

Mitchell writes:

I quickly found a request to a JavaScript file including the API key for the help system which immediately returned an OAuth token for the user.

Thanks to Mitchell's responsible disclosure on 3 July, LinkedIn was able to fix the hole before any mischief came about. It did so by disabling requests without referrers.

A LinkedIn spokesman told The Register that Mitchell's account of the bug proved accurate:

"We can confirm that we were notified of the OAuth vulnerability and took immediate action to fix the issue, which was resolved by our team within 48 hours of being notified."

In return for his trouble, LinkedIn thanked Mitchell with a t-shirt - "All the way from California" - he says.

Hurray for bug bounties!

I guess this bug was pretty small and easy to squash.

Otherwise, maybe Mitchell likely would have gotten a more substantial reward.

A duvet cover, perhaps?

Follow @LisaVaas

Follow @NakedSecurity

Image of mouse and CV and CV courtesy of Shutterstock.


View the original article here

Tuesday, January 3, 2012

As SOPA closes in, hackers look to space for the answer - HEXUS

Each year, a gathering of hackers takes place in Germany, known as the Chaos Communication Congress. The four-day event, now located in Berlin, has been running since 1984 and in 2004 saw a record attendance of 4,230 participants. The congress provides lectures, workshops and discussions on technology, society and utopia.

The 28th Chaos Communication Congress (28C3), which ran with the motto "Behind enemy lines", took place just prior to the New Year, during which time, a scheme to launch satellites into orbit and develop ground stations for tracking was outlined, with the intention of forming a Hackerspace Global Grid, free of censorship and as a backup for hackers during natural or economic disaster. Activists claim that the increasing threat of censorship, such as the recent SOPA Act, had motivated the project, with activist Nick Farr calling out for support for the project in August "The first goal is an uncensorable internet in space. Let's take the internet out of the control of terrestrial entities."

The project is currently in the stage of developing its knowledge-base and understanding, certain limitations must be worked with; typically amateur projects involve sending satellites into low-Earth orbit with balloons, however in non-standard orbits and orbits not situated around the equator, satellites travel quickly around the earth in a non-fixed manner, making them difficult to track. Step one of the project will involve the development of affordable and portable base stations for use in tracking satellite positions.

Satellite Balloon Launch

Mr Farr claims that the project's "only motive" behind the Hackerspace Global Grid is knowledge, "Hackers are about open information ... we believe communication is a human right."

Others question the potential use of such a network as a way to bypass measures implemented to block distribution of intellectual property and copyrighted materials. Whilst the practical usage of such a network remains to be seen, it has raised the question of space rights, though a satellite in orbit would fall under no country's jurisdiction, like-wise no international law exists to protect said satellite from aggressive measures from any country or entity.

An interesting project indeed and a most amazing feat should the community succeed in reaching its goals. We only hope that such satellites are able to remain in orbit without becoming victim to laser fire from a large firm or country.


View the original article here