Facebook patches URL redirection bug

By
Follow google news

Fast fix.

A Facebook URL redirection vulnerability discovered last week was patched just a day after a blog post detailing the bug went live.

Facebook patches URL redirection bug

According to the post by security researcher Dan Melamed, the vulnerability would allow anyone to have a facebook.com link redirect to a website of their choosing “without any restrictions,” simply by removing the “http://” tagged to the end of the URL.

Facebook contacted the researcher to notify him that any suspicious redirects would be caught by their internal Link Shim security tool.

However, Melamed, who included a video highlighting the flaw in his post, wrote that “not all malware/spam” could be caught by Facebook, adding that attackers could easily keep shifting to other malicious links.

The bug landed Melamed $1000.

This article originally appeared at scmagazineus.com

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Apple overhauls security with iOS and macOS 27

Apple overhauls security with iOS and macOS 27

Attackers use SQL injection emails to root Cisco gateways

Attackers use SQL injection emails to root Cisco gateways

Komatsu Australia to move 4000 users to zero trust cloud security

Komatsu Australia to move 4000 users to zero trust cloud security

Optus may ban smart glasses in stores, offices

Optus may ban smart glasses in stores, offices

Log In

  |  Forgot your password?