Seattle.gov Home Page
Link to DoIT Home Page Link to DoIT Home Page Link to DoIT About Us Page Link to DoIT Contact Us Page
Tech Talk Blog Home Page Tech Talk Blog Home Page CityLink Seattle
Welcome to Tech Talk
«    »
Subscribe to
TechTalk Subscribe to RSS feed


Search

Categories


CityLink Seattle

Contributors


Recent Posts


January 2013
M T W T F S S
« Dec   Feb »
 123456
78910111213
14151617181920
21222324252627
28293031  

Tags


Quick Links


Facebook Patches Webcam Snooping Vulnerability

Posted: January 2, 2013 11:41 am
By: - Information Security  

By Brian Donohue

Late last week the social networking giant Facebook patched a particularly voyeuristic security vulnerability in the platform that could have given malefactors the ability to remotely turn on the webcams of other users and post videos to their profiles, according to a Bloomberg News report. The vulnerability was discovered in July by the Indian security firm XY Sec. The firm’s founders, Aditya Gupta and Subho Halder told Bloomberg that Facebook must have considered the bugs serious because they paid XY Sec five times the typical $500 bug bounty price. On his personal website, Gupta said the issue arose from a problem in Facebook’s video upload feature. Evidently Facebook did not have, in Gupta’s words, “proper security checks enforced.” If exploited, it would have given an attacker the ability to secretly record video using another user’s webcam and post that content to the victim’s wall without their knowledge. [HSEC-1.8; Date: 31 December 2012; Source: http://threatpost.com/en_us/blogs/facebook-patches-webcam-snooping-vulnerability-123112]