AusCERT Facebook photo hack may be a test case

Powered by SC Magazine
 

A brute force attack which guessed Facebook URLs may be a breach of Commonwealth and State computer crime laws.

An incident at the AusCERT conference where Facebook photos were taken from a user profile without authorisation and published may be a test case for Commonwealth and state computer crime laws, according to Queensland Police.

In a presentation at the BSidesAu conference held in tandem with AusCERT, an IT security expert siphoned personal photographs from a private Facebook account of the wife of another IT security professional.

Police responded to a complaint of an “alleged hacking incident that saw private material obtain” and arrested Fairfax journalist Ben Grubb at the AusCERT conference. 

Police also seized the journalist’s iPad.

Responding to questions by SC Magazine today, Detective Superintendent Brian Hay said that the incident could be considered a test case for computer crimes laws.

“We are investigating issues of that nature,” Hay said. “Some aspects of it can most certainly be a test case. It is fair to say that jurisdictions are coming to grips with cyber based investigations.”

The exploit presentation was designed to demonstrate a well-known vulnerability in Facebook in which URL addresses linking to photographs in a profile set to private were obtained in a brute force style attack.

While the attack did not crack usernames or passwords, it may have contravened Commonwealth and State computer crime laws which outlaw unauthorised access to electronic files, police said.

The Commonwealth Criminal Code Act states that “access to data held in a computer… by a person is unauthorised if the person is not entitled to cause that access, modification or impairment.”

Other laws also prevent use of a telecommunications carriage service to harass or menace.

The accessed photos may be considered a proceed of crime.

Speaking of the avenues of investigation, Hay said “other actions have been put in place”.

 “We may have people out there that think it is their right to do this. The reality is the online environment is an extension of the community.”

Copyright © SC Magazine, Australia


AusCERT Facebook photo hack may be a test case
 
 
 
Top Stories
Photos: Global Switch opens Sydney East data centre
First stage opened, to some fanfare.
 
ATO releases long-awaited Bitcoin guidance
Everyday investors escape the tax man.
 
Why the Weather Bureau’s new supercomputer is a 'gamechanger'
IT transformation starts to reap results.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Which is the most prevalent cyber attack method your organisation faces?




   |   View results
Phishing and social engineering
  68%
 
Advanced persistent threats
  3%
 
Unpatched or unsupported software vulnerabilities
  12%
 
Denial of service attacks
  7%
 
Insider threats
  11%
TOTAL VOTES: 492

Vote