Skip to main content
  1. Home
  2. Computing
  3. Social Media
  4. Web
  5. News

Vulnerability in Facebook's messaging enabled hackers to insert malicious items

Add as a preferred source on Google

Check Point Software Technologies said on Tuesday that it discovered a vulnerability in the Facebook Messenger app and Facebook Online Chat that could potentially allow a hacker to change the conversation thread. While that doesn’t seem all that alarming at first glance (as compared to hacking an account and grabbing credit card details), the hacker could inject links into the conversation, sending recipients to a malicious website. Malicious videos and photos could be added too.

But there are even bigger risks. The company points out that hackers could manipulate a victim’s message history in a fraud campaign to show that the individual reached a “falsified” agreement. Hackers can also alter important messages in a Facebook chat that could cause legal issues, making the victim look guilty in a potential crime even though he or she is innocent.

Recommended Videos

“By exploiting this vulnerability, cybercriminals could change a whole chat thread without the victim realizing. What’s worse, the hacker could implement automation techniques to continually outsmart security measures for long-term chat alterations,” said Oded Vanunu, head of products vulnerability research at Check Point.

According to the company, researcher Roman Zaikin found the vulnerability. He discovered that messages sent and received in both chat applications have their own identifier “message_id” parameter. The hacker can get this information by sending a request to a specific Facebook address, and once it’s obtained, the hacker can alter the content of the attached message and send it to Facebook’s servers. Thus, users have no idea their messages were altered.

As an example of an attack, the hacker could send a legitimate message to a potential victim. Once the message is received, the hacker can then alter that message to include a malicious link or file. In the video demo shown above, viewers can clearly see Zaikin controlling the entire Facebook chat, texting that cybercriminals can send malicious content through the vulnerability and fully control the conversation. The infection points can be adjusted “seamlessly,” he writes, and the message remotely deleted from the Facebook account to cover the hacker’s tracks.

“Usually, ransomware campaigns last only several days because the infected links and the C&C addresses become known, and blocked by security vendors, forcing the attacker to shut down his activity and begin again from scratch,” the company wrote in a recent blog post. “However, with this vulnerability, the hacker could implement automation techniques to continually outsmart security measures when the command & control servers are replaced.”

While the report sounds a bit scary knowing that Facebook users could potentially send malware to friends unintentionally, the good news here is that Facebook immediately fixed the vulnerability after it was contacted by Check Point. Still, it’s only a matter of time before another vulnerability is found and Facebook users will have to worry about what they send and receive in chat conversations through the social network. Until then, Facebook members can chat to their heart’s content!

Kevin Parrish
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
ChatGPT is recommending scam websites that will steal your credit card info
The chatbot is surfacing fraudulent clones of defunct retail brands, and scammers are deliberately engineering sites to game its recommendations.
ChatGPT running on a laptop.

Scammers have found a new way to reach shoppers: getting ChatGPT to do their marketing for them. According to The Guardian, scam-checking service Ask Silver found that OpenAI's chatbot is recommending fraudulent retail websites built to harvest payment details from unsuspecting buyers. The sites mimic real storefronts and use official-looking URLs, making them difficult to spot without scrutiny.

Defunct brands are a prime target

Read more
McDonald’s new AI drive-thru has to prove it can handle hungry people
After its earlier ordering bot became a punchline, McDonald’s is testing a new system that promises fewer human handoffs.
Architecture, Building, Hotel

McDonald’s is bringing AI back to the drive-thru with a new Google-backed system called ArchIQ, also known as Archy. It’s starting in five locations under the company’s broader “> NEXT” technology push, with a franchisee claiming the system has already handled more than 1 million orders.

The bigger number is the one McDonald’s needs people to trust. About 90% of those orders reportedly needed no human intervention. That sounds promising, but this is not a clean reset. Its earlier IBM-backed AI drive-thru experiment ended after viral mistakes turned automated ordering into a public punchline.

Read more
Logitech’s Mobi Fold is a pocketable folding mouse for folks who despise trackpads
Logitech’s Mobi Fold looks like a tiny productivity taco
Logitech Mobi Fold

Laptop trackpads are fine until you get really busy. Editing a spreadsheet in an airport lounge, juggling tabs in a café, or trying to do proper work on a tiny hotel desk can make you miss the convenience of a mouse. Logitech has the answer to this with the new Mobi Fold, its first ultra-portable foldable mouse.

While a small portable mouse is something people carry, many choose to skip the added bulk, simply choosing to bite the bullet with the trackpad. But the Logitech Mobi Fold can simply fold flat, and can later be unfolded when you need to work. This makes it pretty convenient to carry. Logitech even made the mouse to automatically power on when opened and turn off when folded.

Read more