“Let The Hacking Begin” Declares Person Who Hacked Zuckerberg’s Facebook Page
techcrunch.com
techcrunch.com
Unnamed hacker reinvents IPO, tells world.
Here's 2
a) Users donate money, a la wikipedia (except with FB they can advertise that they are great people and donated, thereby encouraging others to donate)
b) Users pay for access, subscription or some such. If it's optional, paying users get perks (more space for photos, searches across the graph, etc.)
I read it as suggesting the above - just give each facebook user a few shares in facebook.
"Article is wrong.
Mark's profile is here: http://www.facebook.com/zuck
And his like page is here: http://www.facebook.com/pages/...
Neither were hacked.
Someone had setup a fake profile at http://www.facebook.com/markzu... and fooled Techcrunch. Facebook fixed by deleting the fake profile."
A quick copy+paste pretty much confirmed it for me.
Shocker, right?
http://en.wikipedia.org/wiki/Social_business?h=d044aeb71f4e466a552708fc6e3863ef&thanksforthecup=https://www.facebook.com/photo.php%3Fpid%3D393752%26id%3D133954286636768%26fbid%3D170535036312026EDIT
I know 3G is encrypted. What I'm wondering though is if you ever let your phone join an unencrypted wifi network (say at a coffee shop) would it remember the network and then join again automatically the next time you are there?
He'd just have to be logged in, not specifically accessing his fan page, and there's a nice Starbucks near the Facebook campus in Palo Alto that has free (unencrypted) wifi. Or maybe that's all Starbucks these days...
The way iFrames are used by so many 3rd party sites to pull in likes, you don't even need to be on Facebook to be vulnerable.
And I regularly completely wipe personal data from Chrome (which interestingly doesn't give a mechanism to delete cookies on a per-site basis.)
Preferences -> Under the Hood -> Content Settings -> All Cookies and Other Data -> search for site and hit remove.
This is with the dev channel version of Chrome.
I'm not personally familiar with how a high traffic fan page like this is managed, but I guess a fair number of people have access to it to delete spam, forward on interesting messages etc. It seems to me that a lot of those people might have the technical ability to post a new message - they may just be constrained by policy. So that's perhaps dozens of potential unsophisticated targets - interns, junior PR staffers. Like shooting fish in a barrel.
He probably just left his account logged in at a friend's house.
Approach: post links on the contest page to a site that claims to know future questions, write code for you, process your data whatever. They'll get deleted but some staff will inevitably want to check if it's legit.
Method: Today's money is on the IE CSS use after free bug - unpatched and widely available. Get some ie traffic by "this site requires Internet Explorer". Some other month it'd be a jre/flash/quicktime/pdf.
Execution: Transitory system access on one or more clients. Reverse shell or basic payload, good rootkits are expensive. Simplest is just copy cookies/autofills/saved passwords/ssh keys - for extra credit install a keylogger.
Low and behold, poorly_paid_intern not only despams the contest page but does the same for zuck's pr account.
IMO not a local wireless attack - who on the peninsula would have such a idealized view of facebook's financing? Also US citizen+high profile=bad idea, see doing a year for guessing Sarah's yahoo.