• On MovieTome: See the TRAILER for TERMINATOR 4!
September 6, 2008 1:44 PM PDT

Facebook botnet risk revealed

Posted by Elinor Mills
  • Print

Updated Sept. 8 with National Geographic saying the app is not sanctioned by them.

Researchers have created a proof-of-concept application for Facebook that turned the machines of people who added the app to their Facebook page into elements of a botnet that in a demonstration launched denial-of-service attacks on a victim server.

"Social Network Web sites have the ideal properties to become attack platforms," according to a paper entitled "Antisocial Networks:Turning a Social Network into a Botnet," that was authored by five researchers from the Institute of Computer Science in Greece and one from the Institute for Infocomm Research in Singapore.

The demo application, called "Photo of the Day," displays a new photo from National Geographic every day. However, every time someone views the photo, the host computer is forced "to serve a request of 600 Kbytes," according to the paper.

A National Geographic spokeswoman said the app is not sanctioned by her company.

Such a botnet could be used for other types of attacks, such as spreading malware, scanning computers for open ports, and overriding authentication mechanisms that are based on cookies, the paper warned.

The researchers suggested that Facebook and other social networks be careful in designing their platform and application programming interfaces (APIs) so that there are few interactions between the "social utilities they operate and the rest of the Internet."

"More precisely, social network providers should be careful with the use of client side technologies, like JavaScript, etc," the paper says. "A social network operator should provide developers with a strict API, which is capable of giving access to resources only related to the system. Also, every application should run in an isolated environment imposing constraints to prevent the application from interacting with other Internet hosts, which are not participants of the social network. Finally, operators of social networks should invest resources in verifying the applications they host."

In addition, the apps pose privacy risks as well because of the access they have to the data of the people who add the apps to their pages, the paper says.

Similar privacy and security concerns have been raised by others after previous third-party apps have been found to have security holes in Facebook.

Facebook representatives did not return e-mails seeking comment.

(Via ZDNet's Zero Day blog and the Dark Reading blog.)

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
Recent posts from Security
Vietnamese security firm: Your face is easy to fake
Apple suggests Mac users install antivirus software
Europe to get cybercrime alert system
Top-notch Vietnamese software BKAV raises antivirus bar
New 9555 Iridium handset released
Add a Comment (Log in or register) 3 comments
by whataboutthecheese September 6, 2008 7:03 PM PDT
what exactly cost $700,000.00? was it to fix the flaw he exploited?
Reply to this comment
by eee444 September 7, 2008 1:52 AM PDT
The design and programming of the social networks allow a lots of attacks, because they really are initially made by some students, with zero experience in programming and security .
Reply to this comment
by mattumanu September 7, 2008 2:33 PM PDT
Whose computers were botnetted? Come on Cnet, full disclosure!
Reply to this comment
advertisement

In the news now

A tech veteran responds to the recession

LogLogic's Patricia Sueltz heard a clear message about the economy from investors, but she already knows a thing or two about navigating through tough times.


Obama's AG pick on privacy

Eric Holder has criticized the warrantless wiretapping program, but his views on other online policies may not be that far from those of the Bush administration.


About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right