<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Neohaxor.org &#187; social networking</title>
	<atom:link href="http://www.neohaxor.org/tag/social-networking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.neohaxor.org</link>
	<description>InfoSec / Critical Thinking / Misc Crap</description>
	<lastBuildDate>Thu, 21 Oct 2010 16:33:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>Social Media Strategy and Implementation</title>
		<link>http://www.neohaxor.org/2009/09/17/social-media-strategy-and-implementation/</link>
		<comments>http://www.neohaxor.org/2009/09/17/social-media-strategy-and-implementation/#comments</comments>
		<pubDate>Thu, 17 Sep 2009 14:38:58 +0000</pubDate>
		<dc:creator>Nathan Hamiel</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[attack platforms]]></category>
		<category><![CDATA[Attacking]]></category>
		<category><![CDATA[Social Network Applications]]></category>
		<category><![CDATA[social networking]]></category>

		<guid isPermaLink="false">http://www.neohaxor.org/?p=216</guid>
		<description><![CDATA[I will be speaking at MITRE&#8217;s Social Media Strategy and Implementation Workshop in the Washington, DC area on September 28th. My topic is Attacking Social Networks. The goal of the talk is to show some of the darker aspects of social networking. These will be items and attack vectors that people may not be thinking [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter" src="http://farm4.static.flickr.com/3457/3929130756_46a668a69c_o.png" alt="SocmedStrategy" width="300" height="86" /></p>
<p style="text-align: left;">I will be speaking at MITRE&#8217;s <a href="http://socmedstrategy.eventbrite.com/">Social Media Strategy and Implementation Workshop</a> in the Washington, DC area on September 28th. My topic is Attacking Social Networks. The goal of the talk is to show some of the darker aspects of social networking. These will be items and attack vectors that people may not be thinking about. Believe it or not some people are still oblivious to common social network attacks <img src='http://www.neohaxor.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  If you are in the DC area stop on by.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neohaxor.org/2009/09/17/social-media-strategy-and-implementation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>LinkedIn Apps Announced</title>
		<link>http://www.neohaxor.org/2008/11/05/linkedin-apps-announced/</link>
		<comments>http://www.neohaxor.org/2008/11/05/linkedin-apps-announced/#comments</comments>
		<pubDate>Thu, 06 Nov 2008 03:53:05 +0000</pubDate>
		<dc:creator>Nathan Hamiel</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[Social Network Applications]]></category>
		<category><![CDATA[social networking]]></category>

		<guid isPermaLink="false">http://www.neohaxor.org/2008/11/05/linkedin-apps-announced/</guid>
		<description><![CDATA[Business social network LinkedIn announced their LinkedIn Applications today. The applications directory can be viewed here There are only several applications to chose from at the moment. I am sure that number will grow soon. LinkedIn uses Google&#8217;s OpenSocial just like other social networks such as MySpace, Orkut, hi5, etc. I only spent like 5 [...]]]></description>
			<content:encoded><![CDATA[<div align="center">
  <img src="http://farm4.static.flickr.com/3170/3006181865_3d112d7440_m.jpg" />
</div>
<p>Business social network <a href="http://www.linkedin.com" title="LinkedIn">LinkedIn</a> announced their LinkedIn Applications today. The applications directory can be viewed <a href="http://www.linkedin.com/static?key=application_directory" title="here">here</a> There are only several applications to chose from at the moment. I am sure that number will grow soon. LinkedIn uses Google&#8217;s <a href="http://code.google.com/apis/opensocial/" title="OpenSocial">OpenSocial</a> just like other social networks such as <a href="http://www.myspace.com" title="MySpace">MySpace</a>, <a href="http://www.orkut.com" title="Orkut">Orkut</a>, <a href="http://www.hi5.com" title="hi5">hi5</a>, etc. I only spent like 5 minutes looking at a couple of things. So, the following are only my quick thoughts and impressions.</p>
<p>The applications are delivered though the domain lmodules.com. This makes them easy to identify and block if that&#8217;s what you would like to do.</p>
<p>At first glance it appears that the vetting process for LinkedIn is higher than some of the other social networks. They appear to only want known businesses to create applications for their network at this time. This would help root out some possible malicious users. A vetting process is a good first step in thwarting that type of malicious behavior. I didn&#8217;t look at the difficulty in attaining a developer account, but I am assuming it is much more difficult than other social networks like MySpace, Facebok, etc. Now, whether this vetting process will stay this stringent will remain to be seen. These procedures may be relaxed in the future due to demand.</p>
<p>Just because the name has changed doesn&#8217;t mean the threats have changed. As a matter of fact there may actually be more on the table. Business networks such as LinkedIn are more likely to contain real information about people vs other non-professional social networks. Not that people don&#8217;t share enough about their real self on other social networks. This means the same threats exist for the capture of information as on other social networks.</p>
<p>There are still technical threats from social network applications on LinkedIn as well. These are the very same issues as other social networks that we have discussed in the past and demonstrated. Malware distribution, social engineering, attacking clients, information harvesting, click fraud are just some of these threats from social network applications. Moral of the story is be careful. Don&#8217;t install apps you don&#8217;t need, even though you may do so on your iPhone <img src='http://www.neohaxor.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>So all in all the threats are the same with LinkedIn as any other social networks that employ applications. However, with a more stringent vetting process this should reduce the possibilities for malicious by making accounts harder to get.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neohaxor.org/2008/11/05/linkedin-apps-announced/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Me and CPU Mag This Month</title>
		<link>http://www.neohaxor.org/2008/11/03/me-and-cpu-mag-this-month/</link>
		<comments>http://www.neohaxor.org/2008/11/03/me-and-cpu-mag-this-month/#comments</comments>
		<pubDate>Mon, 03 Nov 2008 21:15:10 +0000</pubDate>
		<dc:creator>Nathan Hamiel</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[Social Network Applications]]></category>
		<category><![CDATA[social networking]]></category>

		<guid isPermaLink="false">http://www.neohaxor.org/2008/11/03/me-and-cpu-mag-this-month/</guid>
		<description><![CDATA[For those of you that care, there is a caricature of me on the cover of the November issue of CPU Magazine. In the back of the magazine there is some Q&#38;A with me mostly about social networks. It&#8217;s probably stuff you have heard Shawn and I say before, but cool nonetheless. So if you [...]]]></description>
			<content:encoded><![CDATA[<p>For those of you that care, there is a caricature of me on the cover of the November issue of <a href="http://www.computerpoweruser.com/" title="CPU Magazine">CPU Magazine</a>. In the back of the magazine there is some Q&amp;A with me mostly about social networks. It&#8217;s probably stuff you have heard Shawn and I say before, but cool nonetheless. So if you are in your favorite book store check out the magazine and see what you think.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neohaxor.org/2008/11/03/me-and-cpu-mag-this-month/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Attacking Password Resets w/ Social Networks</title>
		<link>http://www.neohaxor.org/2008/10/02/attacking-password-resets-with-social-networks/</link>
		<comments>http://www.neohaxor.org/2008/10/02/attacking-password-resets-with-social-networks/#comments</comments>
		<pubDate>Thu, 02 Oct 2008 14:02:09 +0000</pubDate>
		<dc:creator>Nathan Hamiel</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[password reset]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[social networking]]></category>

		<guid isPermaLink="false">http://www.neohaxor.org/2008/10/02/attacking-password-resets-with-social-networks/</guid>
		<description><![CDATA[Password Reset: Your passport to a fuxored account. Password Reset Methods Vulnerable? Really? Get out of here, you mean that many password reset methods are vulnerable to attack? You have to be kidding. The fact that people think vulnerable password reset is newsworthy have got to be crazy. This is something that many of us [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://farm4.static.flickr.com/3209/2901758413_3e2b6301a6.jpg" alt="" width="100" height="145" /></p>
<p><strong>Password Reset:</strong> Your passport to a fuxored account.</p>
<p>Password Reset Methods Vulnerable? Really? Get out of here, you mean that many password reset methods are vulnerable to attack? You have to be kidding. The fact that people think vulnerable password reset is newsworthy have got to be crazy. This is something that many of us have been talking about for years. Now Sarah Palin&#8217;s email gets attacked and it is big deal. It amazes me why we always wait to get screwed by something before we fix it.</p>
<p>Why does everything in the security world have to be a response to something. Ok, not the security world but the business security world. They are definitely two different entities. I am truly tired of reactive security. Just think if other professions followed this reactive model, like a cop asking for a bullet proof vest after they have already been shot. Nobody can say they didn&#8217;t see this coming either. People make more of their life known through social networks, photo sharing, and blogs than ever before. The simple password reset questions just don&#8217;t hold up.</p>
<p>There is a lot of unnecessary fear about data from social networks being used to steal someone&#8217;s identity. Although this is mostly FUD, social networks can be a great source for password recovery data. A while back we recovered a password (with his permission of course) from my friend Brian&#8217;s <a title="Sprint" href="http://www.sprint.com/">Sprint</a> account using data from his <a title="MySpace" href="http://www.myspace.com">MySpace</a> page. This is when we were first starting our research for the social network hacking project.</p>
<p>Let&#8217;s take a step back from social networks for a sec, would your friends, co-workers, significant other, etc. be able to recover your password with the information they know about you? If the answer to that question is yes, then you need to change something. Passwords should be something that you know, not you and a couple of other people.</p>
<h3>What Types of Data are on Social Networks?</h3>
<p>The information that people put on their social network pages range from minimal to wildly over the top. Some people even go above and beyond by posting survey questions that tell a lot about their personalities. Although they want to show off the depth of their personality, all it really does is show off the shallowness of their brain.</p>
<p>Social networks by their default nature basically allow you to &#8220;friend&#8221; the world. The information on people&#8217;s social network page typically contains information that was previously only known to traditional friends and acquaintances. This can be a huge problem for the password reset mechanism, not to mention a person&#8217;s privacy. If it&#8217;s deep and kinda scary from a privacy standpoint then it is probably on a social network. Remember when I mentioned if your friends knew enough about you to reset your password then you are in trouble, well you just friended the world with the information from your social network profile. Beyond standard profile information there are a users actions taken on a social network site and possibly social network applications that are being used as well. All of this information can be leveraged when attacking a password reset mechanisms.</p>
<p>You can use an email address to look up people&#8217;s accounts on social networking sites. On the flip side, someone social network profile might directly tell you a person&#8217;s email address or you can use the search features of the social network to query owner&#8217;s of certain email addresses. There are no secrets in social networking <img src='http://www.neohaxor.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<h3>Email Accounts are Gold</h3>
<p>With password resets an email account is really the jackpot. Many password reset mechanisms, including the ones from social networks, rely on sending either the password or a temporary password to the email address of the account owner. Someone who gets their email account compromised might just find that they have every other account tied to that email account compromised as well. I mean, it wouldn&#8217;t be a far stretch to figure that out once someone had access to the email account. Just think of all the crap that sites like Amazon, eBay, MySpace, Facebook, etc. send to your email account.</p>
<h3>Typical Password Questions</h3>
<p>Typical password recovery questions really vary in complexity from site to site. What is the problem with password recovery questions in general? Well, they are not typically made up of data that is private. Unlike a password which is supposed to be something that only you know, recovery questions may be known to many people around you.</p>
<p>Here are some questions from Yahoo:</p>
<ul>
<li>Where did you meet your spouse?</li>
<li>What was the name of your first school?</li>
<li>Who was your childhood hero?</li>
<li>What is your favorite pastime?</li>
<li>What is your favorite sports team?</li>
<li>What is your father&#8217;s middle name?</li>
<li>What was your hight school mascot?</li>
<li>What make was your first car or bike?</li>
<li>What is your pets name?</li>
</ul>
<p>Some of these questions look like questions that social networks ask when you are filling out a profile, don&#8217;t they? If not questions they ask, certainly data that people put on their social network profiles or divulge through other means on a social network.</p>
<h3>The Obvious</h3>
<p>Take a glance at someone&#8217;s profile or maybe your profile on a social network. From just this page without further probing there may be an enormous amount of information. Depending on the mechanism that is being attacked, it may be all that is needed. Here is an example of some of the things that may be found just on the profile page:</p>
<ul>
<li>Name</li>
<li>Date of Birth</li>
<li>Hometown</li>
<li>Current town</li>
<li>Favorite movies, artists, music, people, TV, sports teams, etc</li>
<li>High School</li>
<li>College</li>
<li>Personal description</li>
<li>Personality traits</li>
<li>Networks and Groups</li>
<li>Relationship information</li>
<li>Family information</li>
<li>Employer</li>
</ul>
<p>The list really goes on and on. Remember that many people are on multiple social networks. Checking out other social networks may fill in the blanks. It is easy to see why this information could be a problem and I don&#8217;t think it needs any further explanation.</p>
<h3>The Not So Obvious</h3>
<p>Some data is not so obvious and might not be directly spelled out. This may be information that has to be aggregated or inferred from the profile data, friends list, blog, group, network, etc.</p>
<ul>
<li>Photos and photo tags</li>
<li>Comments on other profiles</li>
<li>Photo data (cloths, background, other individuals, etc)</li>
<li>Pets</li>
<li>Children</li>
<li>Siblings</li>
<li>Relatives (potentially ones with your mother&#8217;s maiden name?)</li>
<li>Potential usernames</li>
<li>Instant messenger data</li>
<li>Blogs and comments in friends&#8217; blogs</li>
<li>Favorite teachers</li>
<li>Sexual preference</li>
<li>Religious views</li>
<li>Political views</li>
</ul>
<p>The data is really limitless, but after all isn&#8217;t that what a nice web 2.0 application is supposed to provide? On the surface some of this data may seem silly for password resets but it is really not. This not so obvious information can be really helpful when when non-standard questions are used in the password reset process. This typically happens when people are left to their own devices when creating security questions. They typically create questions that are common and familiar to them. Stupid things like pet&#8217;s names, favorite teams, favorite TV shows, etc.</p>
<p>Just think for a moment about tagging. People may tag photos themselves with useful information. Also, friends may tag people in photos helping better define a person&#8217;s relationships with people and activities they are involved in. The URL of the social network may lead you to potential usernames / IM information such as www.myspace.com/(username). Maybe the data is completely visual like photo data. A lot of information can be obtained by looking at pictures. Favorite places, sports teams, cars, and countless other possibilities. You name it, people like pictures with their favorite things.</p>
<p>The actions people take on social networks helps better define relationships, networks, group affiliations, and activities. The person may place comments on other people&#8217;s photos, profiles, walls, blogs, etc. You may see comments like &#8220;That is why you are my BFF&#8221;. You may also see that someone is a member of a political party or religious group. People may discuss on boards or blogs about certain things happening in their life. Sharing is caring right?</p>
<p>So what you get in the end is a clear picture of who these people are. You get their likes, dislikes, friends, and affiliations are all in a nice clean package. You may have never even met this person but you have all of the information a traditional friend may have, possibly more.</p>
<h3>Need a bit more?</h3>
<p>If you almost have the nail in the coffin then you can turn to other sites to complete the task. You could look for name / username collisions on other sites to gain more data. You could take their high school and age information and find out who they went to school with. The possibilities are endless.</p>
<h3>The User&#8217;s Choice</h3>
<p>When people are given the option to choose their own security it has historically been bad. There is nothing that seems to suggest that allowing user&#8217;s to choose their security will get any better, so some of this may be wasted breath.</p>
<p>When looking at sites like Google, it seems they have slightly better security questions. Questions such as your library card number, frequent flyer number, etc. I think sites like these with better security questions probably have a high amount of people that end up just choosing their own questions when this option is available. People don&#8217;t seem to understand that this isn&#8217;t a function that you are going to use everyday. It is ok and preferable to use data that you may not be able to recall without looking up.</p>
<h3>So What Can We Do?</h3>
<p>The problem of personal data leakage isn&#8217;t going to stop until people realize the potential impacts of their data being strung out for the whole world to see. I personally don&#8217;t think this will change, in fact, I think with time it will get a lot worse. We live in this voyeuristic, virtual world where people create digital representations of how they see themselves. I think that has an appeal to many people, especially those who don&#8217;t particularly find their lives that exciting.</p>
<p>Don&#8217;t play by the rules when dealing with a sites password reset questions. Put blatantly wrong, hard to guess, or nonsensical information in to the answer blocks. This will make any information gathered on you useless when attempting to recover your password.</p>
<p>It seems that many sites want you to log in. You shouldn&#8217;t use the same password on every site. Use a trusted password safe such as <a title="KeePass" href="http://keepass.info/">KeePass</a> to store your login credentials. KeePass is open source and multi-platform. Using a mechanism like this allows you to be in control of your password recovery along with allowing you to use different passwords for different sites. It would also be a good idea to back up the database of whatever password safe you choose to use as well. Just a thought <img src='http://www.neohaxor.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>The biggest mistake someone can make is thinking that there is nobody out there that gives enough of a crap about them to attack their accounts. People do weird things. Anybody is capable of just about anything. This isn&#8217;t being paranoid, it&#8217;s being safe. Think of it as locking the door on your house when you leave, only instead of your valuables you are protecting your data.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neohaxor.org/2008/10/02/attacking-password-resets-with-social-networks/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>See You At PhreakNIC 12</title>
		<link>http://www.neohaxor.org/2008/09/18/see-you-at-phreaknic-12/</link>
		<comments>http://www.neohaxor.org/2008/09/18/see-you-at-phreaknic-12/#comments</comments>
		<pubDate>Thu, 18 Sep 2008 19:44:16 +0000</pubDate>
		<dc:creator>Nathan Hamiel</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[Social Network Applications]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[speaking]]></category>

		<guid isPermaLink="false">http://www.neohaxor.org/2008/09/18/see-you-at-phreaknic-12/</guid>
		<description><![CDATA[Hello Everyone. I just wanted everyone to know that Shawn Moyer and I will be speaking at PhreakNIC 12. We are going to do the Satan is on my Friends List talk again. There were people who didn&#8217;t get to see it out in Las Vegas, and well, since BHJP is in a different part [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.phreaknic.info/pn12/images/title.png" /></p>
<p>Hello Everyone. I just wanted everyone to know that Shawn Moyer and I will be speaking at <a href="http://www.phreaknic.info" title="PhreakNIC 12">PhreakNIC 12</a>. We are going to do the Satan is on my Friends List talk again. There were people who didn&#8217;t get to see it out in Las Vegas, and well, since BHJP is in a different part of the world we figured if people still wanted to see it we would do it again in the United States. We will have some updates so it won&#8217;t totally be the same talk we did in Vegas.</p>
<p>If you aren&#8217;t familiar with PhreakNIC it is a small conference in Nashville, TN. It&#8217;s loads of fun, there is great people, great conversation, and no vendor overload. I highly encourage people to go.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neohaxor.org/2008/09/18/see-you-at-phreaknic-12/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Users Leverage Developer Accounts</title>
		<link>http://www.neohaxor.org/2008/09/17/facebook-users-leverage-developer-accounts/</link>
		<comments>http://www.neohaxor.org/2008/09/17/facebook-users-leverage-developer-accounts/#comments</comments>
		<pubDate>Wed, 17 Sep 2008 17:43:19 +0000</pubDate>
		<dc:creator>Nathan Hamiel</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[social networking]]></category>

		<guid isPermaLink="false">http://www.neohaxor.org/2008/09/17/facebook-users-leverage-developer-accounts/</guid>
		<description><![CDATA[I find this funny, here is an article where it talks about Facebook users leveraging developer accounts they signed up for, so they can go back to the old Facebook. When you have the developer application installed it puts a link at the top of your profile page to switch back to the old Facebook. [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://farm4.static.flickr.com/3155/2865152675_e6b1d243ba.jpg" alt="" /></p>
<p>I find this funny, <a title="here" href="http://www.alleyinsider.com/2008/9/facebook-users-who-hate-change-making-facebook-developers-hate-facebook-users">here</a> is an article where it talks about <a title="Facebook" href="http://www.facebook.com">Facebook</a> users leveraging developer accounts they signed up for, so they can go back to the old Facebook. When you have the developer application installed it puts a link at the top of your profile page to switch back to the old Facebook. This makes sense since developers may have to maintain functionality on the old Facebook as well as the new. The funny thing is, I have had a developer account almost as long as I have had a Facebook account. I just assumed that option was on everyone&#8217;s page. It is a nice little hack, although Facebook is going to turn that option off soon.</p>
<p>It also seems that the users flooded the developer message boards voicing their distaste for the new Facebook. Ah&#8230; well&#8230; I hate to break it to them, but shhhh&#8230; those message boards are for the apps developers. There are Facebook staff that hang out and such, but all you are doing is irritating the person who wrote that stupid app you put on your page and don&#8217;t use. Stop! You are distracting them from doing input validation <img src='http://www.neohaxor.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>I don&#8217;t really understand this UI rebellion. Who cares. I mean, really you can do the same stupid things you could do previously. If you don&#8217;t like it use <a title="MySpace" href="http://www.myspace.com">MySpace</a>. The more you look at Facebook the more it looks less and less like a social network anyway. The other day on TechCrunch there was an article called <a title="Facebook Isn't A Social Network." href="http://www.techcrunch.com/2008/09/15/facebook-isnt-a-social-network-and-dont-try-to-make-new-friends-there/">Facebook Isn&#8217;t A Social Network. And Stop Trying to Make New Friends There</a>. I agree with this viewpoint. MySpace and other social networks are much more conducive to meeting new people and finding individuals with similar interests. It all depends on what you use a social network for.</p>
<p>I have an idea for all of the people who don&#8217;t like the new Facebook, the best way to rebel, is to quit using Facebook. That will get their attention. I know it won&#8217;t happen, but it isn&#8217;t like there aren&#8217;t alternatives. I mean, what does Facebook give you that other social networks won&#8217;t? The answer is nothing. Most people have accounts on multiple soc nets anyway. There are some 800,000 users in the I hate the new Facebook group. If they all quit using their accounts, that would have an impact. Do it or quit complaining. The choice is yours. The reason nothing changes is because they know you won&#8217;t leave.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neohaxor.org/2008/09/17/facebook-users-leverage-developer-accounts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook Application Verification = Fail</title>
		<link>http://www.neohaxor.org/2008/09/16/facebook-application-verification-fail/</link>
		<comments>http://www.neohaxor.org/2008/09/16/facebook-application-verification-fail/#comments</comments>
		<pubDate>Tue, 16 Sep 2008 13:59:01 +0000</pubDate>
		<dc:creator>Nathan Hamiel</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Social Network Applications]]></category>
		<category><![CDATA[social networking]]></category>

		<guid isPermaLink="false">http://www.neohaxor.org/2008/09/16/facebook-application-verification-fail/</guid>
		<description><![CDATA[Recently Facebook announced their Application Verification Program in an attempt to give user&#8217;s assurances that particular applications are secure. I think the intent is good but the implementation may actually cause more harm than good. Giving users an assurance that a malicious applications are secure can cause a lot of damage. People with assurances are [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://farm4.static.flickr.com/3156/2863334042_2ded75c92a.jpg" alt="" /></p>
<p>Recently <a title="Facebook" href="http://www.facebook.com">Facebook</a> announced their <a title="Application Verification Program" href="http://developers.new.facebook.com/verification.php">Application Verification Program</a> in an attempt to give user&#8217;s assurances that particular applications are secure. I think the intent is good but the implementation may actually cause more harm than good. Giving users an assurance that a malicious applications are secure can cause a lot of damage. People with assurances are a lot more loose with their actions where they may normally not be with no expectation of security.</p>
<p>Given the way many of Facebook&#8217;s applications are written it doesn&#8217;t lend itself to a proper review. The Facebook team is going to have to do reviews of submitted code that does not run on Facebook servers. This would only be a snapshot of the code at that given time. After the verification procedures are done, the developer can make whatever changes they want. They could change the verified app to a malicious app at will. I am getting so tired of security measures that don&#8217;t address the real problems. They are a waste of time. The only thing this verification program may do is stop the idiot who just learned PHP from creating the HackMe Back of social network applications. It doesn&#8217;t address the major problem that attackers are gaining access to the API and attacking social network users.</p>
<p>The best way to protect against malicious applications is to control the access to the API in the first place. Don&#8217;t just let anyone access the API and only need 5 friends to publish the app. Proper vetting procedures would go a long way in curbing the amount of malicious applications that get published on Facebook and other social networks. Why don&#8217;t the major social networks have vetting procedures for API access? It completely blows my mind, but that&#8217;s social network culture for ya.</p>
<p>Social networks are riding a thin line with security as it is. Introducing security measures that aren&#8217;t effective only cause more confusion on the part of their users. Social networks should strive to create a balance between functionality and security for everyone&#8217;s sake. Will that happen? Only time will tell. One thing is for sure though, attacks on social networks are only going to go up. The more surface you give an attacker the more options and success they are going to have.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neohaxor.org/2008/09/16/facebook-application-verification-fail/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>My Impression of Facebot = Old News</title>
		<link>http://www.neohaxor.org/2008/09/13/my-impression-of-facebot-old-news/</link>
		<comments>http://www.neohaxor.org/2008/09/13/my-impression-of-facebot-old-news/#comments</comments>
		<pubDate>Sat, 13 Sep 2008 21:11:54 +0000</pubDate>
		<dc:creator>Nathan Hamiel</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Facebot]]></category>
		<category><![CDATA[social networking]]></category>

		<guid isPermaLink="false">http://www.neohaxor.org/2008/09/13/my-impression-of-facebot-old-news/</guid>
		<description><![CDATA[Quite a few people have emailed me asking me what I thought about the Facebot application that was recently released. The paper is located here. Basically a group of people created an application that they published on Facebook that did click fraud. They hijacked simple requests through an application called Photo of the Day using [...]]]></description>
			<content:encoded><![CDATA[<p>Quite a few people have emailed me asking me what I thought about the Facebot application that was recently released. The paper is located <a href="http://www.ics.forth.gr/~elathan/publications/facebot.isc08.pdf" title="here">here</a>. Basically a group of people created an application that they published on <a href="http://www.facebook.com" title="Facebook">Facebook</a> that did click fraud. They hijacked simple requests through an application called Photo of the Day using HTML IMG tags, you know, the same thing we did on <a href="http://www.myspace.com" title="MySpace">MySpace</a> without even having to create an application, however, we had <a href="http://code.google.com/apis/opensocial/" title="OpenSocial">OpenSocial</a> applications that did the same thing, and a little worse <img src='http://www.neohaxor.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>They said they did it to prove you could turn a social network in to a botnet, you know, the same thing that we already talked about and demonstrated at both <a href="http://www.blackhat.com" title="Black Hat">Black Hat</a> and <a href="http://www.defcon.org" title="Defcon">Defcon</a> this year. As a matter of fact a copy of our presentation can be obtained here: <a href="http://www.hexsec.com/docs/Satan_Blackhat_Defcon.pdf" title="Satan_Blackhat_Defcon">Satan_Blackhat_Defcon</a></p>
<p>The title of their paper is &#8220;Antisocial Networks: Turning a Social Network into a Botnet&#8221;. The title of our HOPE presentation that we had to back out of was &#8220;Antisocial Networking: Vulnerabilities in Social Nets&#8221;. You can see this <a href="http://www.2600.com/news/view/article/10650" title="here">here</a> from back in June. I am not quite sure what to think about all this, I guess it could all be coincidence. Like I said, I don&#8217;t know.</p>
<p>Now on Facebook the way you would have to go about turning their users in to a botnet is by creating an application. Facebook doesn&#8217;t allow linking to offsite content the way MySpace does. So if you want to use img tags, meta tags, and iframe tags you would have to use them in an application that you created.</p>
<p>So, my impression is Yup. Everything we talked about at Black Hat and Defcon. It&#8217;s old news, not sure why anyone is making a big deal or even writing about it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neohaxor.org/2008/09/13/my-impression-of-facebot-old-news/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Request Forgeries on MySpace</title>
		<link>http://www.neohaxor.org/2008/08/13/request-forgeries-on-myspace/</link>
		<comments>http://www.neohaxor.org/2008/08/13/request-forgeries-on-myspace/#comments</comments>
		<pubDate>Thu, 14 Aug 2008 04:36:35 +0000</pubDate>
		<dc:creator>Nathan Hamiel</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Black Hat]]></category>
		<category><![CDATA[Defcon]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[social networking]]></category>

		<guid isPermaLink="false">http://www.neohaxor.org/2008/08/13/request-forgeries-on-myspace/</guid>
		<description><![CDATA[I thought I would take a bit to explain some request forgeries Shawn Moyer and I found on MySpace and a couple of other social networking sites. These were demonstrated at our presentations at both Black Hat and Defcon. We found several functions were we could modify the request and trick the user&#8217;s browser in [...]]]></description>
			<content:encoded><![CDATA[<p>I thought I would take a bit to explain some request forgeries <a href="http://www.agurasec.com" title="Shawn Moyer">Shawn Moyer</a> and I found on MySpace and a couple of other social networking sites. These were demonstrated at our presentations at both <a href="http://www.blackhat.com" title="Black Hat">Black Hat</a> and <a href="http://www.defcon.org" title="Defcon">Defcon</a>. We found several functions were we could modify the request and trick the user&#8217;s browser in to making requests they didn&#8217;t intend. This is classic CSRF with an added advantage. The two demos we showed allowed us to get a victim&#8217;s web browser to send friend requests to a user of our choice and the other logged users out. There were also some more stealthy actions we could have taken such as block user communications from all visitors to their home page.</p>
<p>What made these request forgeries that much worse was that fact that we inserted them on the site we were attacking. In our case we used an image tag that linked to some offsite Python code doing a redirect back to MySpace. This basically gave us almost a 100% success rate due to the fact that we knew the user was viewing the page at that particular time. We could not only do this to profiles that we own but also anywhere that allows us to link to offsite content such as profile comments, photo comments, blog postings, classifieds, and many others.</p>
<p>I am not sure if people realize how serious this can be to the particular social network owner. If attacks using these particular methods propagate though the social network by some automated, semi-automated, or even planned method they could potentially cause DoS conditions that would be hard for the lay person to identify and fix. Being logged out constantly would be bad but more covertly someone could get you to block communication with everyone that visits your profile. That could be hard to catch.</p>
<h3>Offsite Content = Fail</h3>
<p>When you allow linking to offsite content you are inviting failure. This content is beyond the control of the particular social network. As an attacker all you care about is GET that the browser is using to retrieve the content. The fact that it fails on the return is inconsequential. What we did was use what was available to us on a MySpace profile page and comments, which was the IMG tag. We used the IMG tag to get the victims browser to make a request for an image that didn&#8217;t exist. This GET request from the browser hit a redirect which then sent a crafted GET back to MySpace with whatever payload we wanted. In our case it was a friend request or a logout.</p>
<p>Just think if MySpace disabled linking to offsite content, suddenly millions of MySpace profiles would instantly looked much better <img src='http://www.neohaxor.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<h3>Same Site Content = Fail</h3>
<p>Sometimes content on the same site can equal fail as well. If the social network allows certain HTML tags such as iframes or meta tags these can be used to construct request forgeries as well. The src attribute of the iframe tag and the meta refresh can be used to specify other locations in which to request content. These would not even have to leave the social network and be redirected. This would make it SSRF (Same Site Request Forgery) or just RF (Request Forgery). Hahah. Ok, now this is getting silly, let&#8217;s move on.</p>
<h3>Combining Technical and Social Attacks</h3>
<p>Think about the impacts from combining a couple of these attacks with a social attack. For instance, you may want to take over the profile of another user. Most likely, based on privacy settings, you can see the friends of a particular individual. You tag their profile with a request forgery that blocks communication to all visitors of the profile. You then create a new profile of the person you want to impersonate and send their friends new friend requests. You could state that you forgot your password and want to re-add them as friends. Combined technical and social attacks can lead to a higher degree of success depending on what the attacker&#8217;s goal is.</p>
<p>This blended threat is going to be much more common in the future and we are starting to see this now. Sites that use social methods to get people to download malware or take an action that an attacker wants. The reason these attacks are so successful is the implied trust of the user and their complacency. Be on the lookout for this more and more in the future, especially as defenses go up.</p>
<h3>Fixing Your Profile</h3>
<p>If your comments, photo pages, blog, or some other part of your profile tagged there are a couple of steps you can take to remove the content and protect yourself in the future. Since the profile content is rendered HTML it takes a few steps to remove the content. In the case of a logout, comments will be rendered and log you out prior to you being able to remove them. What you can do is use something to block the domain that is calling the logoff, which will most likely be collect.myspace.com. Once you block that domain you can go ahead and remove the content, then re-enable collect.myspace.com. If it is something such as a communication block you can go ahead and just remove the content (which ever it may be) and then use some out of social network band to contact your friends.</p>
<p>You should also go through your profile settings and ensure that HTML comments are turned off wherever possible. This will help give you a better handle on what content people have the ability to put on your profile. Of course, this doesn&#8217;t help you visiting other people&#8217;s pages.</p>
<p>If you notice shenanigans where you suspect someone is doing something malicious you should report it to the abuse contact at MySpace or at the social network you are using. That is what they are there for. The MySpace security team is working hard behind the scenes looking for items such as described here, so make sure if you notice shenanigans that you report it to them.</p>
<p>Oh&#8230; I am already on their watch list so don&#8217;t blame it on me because they will know it wasn&#8217;t <img src='http://www.neohaxor.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  0_0 They are watching me 0_0</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neohaxor.org/2008/08/13/request-forgeries-on-myspace/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Black Hat / Defcon Presentation</title>
		<link>http://www.neohaxor.org/2008/08/10/black-hat-defcon-presentation/</link>
		<comments>http://www.neohaxor.org/2008/08/10/black-hat-defcon-presentation/#comments</comments>
		<pubDate>Sun, 10 Aug 2008 20:54:09 +0000</pubDate>
		<dc:creator>Nathan Hamiel</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[social networking]]></category>

		<guid isPermaLink="false">http://www.neohaxor.org/2008/08/10/black-hat-defcon-presentation/</guid>
		<description><![CDATA[I just wanted to make a quick post to let people know our updated Black Hat and Defcon slides we used for those conferences have been posted. These are our updated slides. You can download them Here Thank you to all who showed up, we hope you enjoyed the presentation. Let us know if you [...]]]></description>
			<content:encoded><![CDATA[<p>I just wanted to make a quick post to let people know our updated Black Hat and Defcon slides we used for those conferences have been posted. These are our updated slides. You can download them <a href="http://www.hexsec.com/docs/Satan_Blackhat_Defcon.pdf" title="Link to our Black Hat / Defcon slides">Here</a></p>
<p>Thank you to all who showed up, we hope you enjoyed the presentation. Let us know if you have any further questions.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.neohaxor.org/2008/08/10/black-hat-defcon-presentation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

