meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, October 1st 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 1 October 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Facebook Leak; Telegram leaks IPs; Browser Notifications; DDE Code Injection

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, October 1st, 2018 edition of the Sands and Storm Center's Stormcast. My name is Johannes Ulrich, and I'm recording from Honolulu, Hawaii.

0:13.2

Of course, the big news on Friday was Facebook announcing that 50 million user profiles were leaked due to a vulnerability in Facebook's

0:25.3

view as feature. Using this feature, you were able to see your profile how another user would

0:32.9

experience your profile. But apparently this feature gave it hackers access to

0:39.1

arbitrary users Facebook profile now according to Facebook the latest number of

0:45.3

affected profiles is around 50 million given that Facebook has some around 2

0:52.1

billion different profiles it roughly affects 2.5% of Facebook users.

0:59.0

I don't believe Facebook has notified affected users yet.

1:04.0

However, if you are affected, then Facebook should have logged out your account.

1:10.0

So if you're going to Facebook and all of a sudden need to log in again,

1:14.4

well, then probably your account was one of those 50 million.

1:19.2

It's also not known if these accounts were targeted in some manner,

1:23.1

if these were just random accounts.

1:25.9

There was also an announcement late last week that someone was going to do a live stream

1:32.0

of the leading Mark Zuckerberg's Facebook account.

1:35.9

Later after the press release came out about the leak, this video stream announcement was

1:42.4

rescinded so possible that it was related somehow to this vulnerability.

1:48.0

Initially, Facebook just disabled the VUAS feature.

1:52.0

Not sure if it actually has been enabled again, but Facebook said that they had fixed the flaw.

1:59.0

Features like this are of course always a little bit tricky to implement, so it's very

2:03.6

possible that Facebook temporarily mapped the target users' permissions to your account in order

2:10.6

to display your profile as this particular user would see it, and by mapping these permissions,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.