 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Irregular Expressions &#187; facebook</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/Irregular-Expressions/tag/facebook/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions</link>
	<description>Insight into current security related events and exploits, including virtualization security and tips.</description>
	<lastBuildDate>Sun, 28 Apr 2013 08:00:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Facebook Forensics</title>
		<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/facebook-forensics/</link>
		<comments>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/facebook-forensics/#comments</comments>
		<pubDate>Fri, 30 Mar 2012 06:18:27 +0000</pubDate>
		<dc:creator>Dan O'Connor</dc:creator>
				<category><![CDATA[facebook]]></category>
		<category><![CDATA[Forensics]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/Irregular-Expressions/facebook-forensics/</guid>
		<description><![CDATA[Yay for forensics. http://www.wired.com/threatlevel/2012/03/facebook-ownership-forensics/ Faking forensic data seems simple from the outside but when you really get to the nitty gritty it is not the simplest problem to solve. This case revolves around a contract that gives him half owner ship of Facebook. The details are in the story. The main point here is that [...]]]></description>
				<content:encoded><![CDATA[<p>Yay for forensics.</p>
<p>http://www.wired.com/threatlevel/2012/03/facebook-ownership-forensics/</p>
<p>Faking forensic data seems simple from the outside but when you really get to the nitty gritty it is not the simplest problem to solve.<br />
This case revolves around a contract that gives him half owner ship of Facebook.</p>
<p>The details are in the story.  The main point here is that files just don&#8217;t appear on a system.  Also if you want to clean your drive reinstalling windows just does not cut it.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/facebook-forensics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The evolution of facebook click jacking</title>
		<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/the-evolution-of-facebook-click-jacking/</link>
		<comments>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/the-evolution-of-facebook-click-jacking/#comments</comments>
		<pubDate>Wed, 10 Nov 2010 04:52:24 +0000</pubDate>
		<dc:creator>Dan O'Connor</dc:creator>
				<category><![CDATA[click jacking]]></category>
		<category><![CDATA[clickjacking]]></category>
		<category><![CDATA[facebook]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/Irregular-Expressions/the-evolution-of-facebook-click-jacking/</guid>
		<description><![CDATA[How much further can click jacking in facebook go? Right now the main ones that I have seen are working to either gather information (or just a prof of concept) and try to use a browser vulnerability on the redirected page to infect the host. Another from the Sophos blog tries to get you on [...]]]></description>
				<content:encoded><![CDATA[<p>How much further can click jacking in facebook go?</p>
<p>Right now the main ones that I have seen are working to either gather information (or just a prof of concept) and try to use a browser vulnerability on the redirected page to infect the host.</p>
<p>Another from the Sophos blog tries to get you on a monthly cell plan.</p>
<p>http://nakedsecurity.sophos.com/2010/11/09/jetblue-tickets-scam-spreads-via-facebook-jezebel/</p>
<p>What else could you do?</p>
<p>What about harvesting facebook passwords?  What good is that, well I can&#8217;t say the number but I bet there is more people than not that use the same password for everything!  You could also use this in research with passwords and combine information such as what people do, age, work history, and geographical location to build a model for what kind of password they would use. Why not?</p>
<p>I could also see targeted spear fishing attacks with click jacking.</p>
<p>Sounds like something fun!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/the-evolution-of-facebook-click-jacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>facebook session hijacking</title>
		<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/facebook-session-hijacking/</link>
		<comments>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/facebook-session-hijacking/#comments</comments>
		<pubDate>Fri, 29 Oct 2010 05:10:31 +0000</pubDate>
		<dc:creator>Dan O'Connor</dc:creator>
				<category><![CDATA[facebook]]></category>
		<category><![CDATA[hijack]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/Irregular-Expressions/?p=432</guid>
		<description><![CDATA[I love it when people do all of the work for you. http://codebutler.github.com/firesheep/ Firesheep is a FireFox plugin to hijack FB session, it looks really good. There is a slide show here http://codebutler.github.com/firesheep/tc12/ With a short demo. Here is a shot of the capture running. http://codebutler.github.com/firesheep/tc12/#40 This will work with twitter, facebook, and google. Anything [...]]]></description>
				<content:encoded><![CDATA[<p>I love it when people do all of the work for you.</p>
<p>http://codebutler.github.com/firesheep/</p>
<p>Firesheep is a FireFox plugin to hijack FB session, it looks really good.</p>
<p>There is a slide show here</p>
<p>http://codebutler.github.com/firesheep/tc12/</p>
<p>With a short demo.</p>
<p>Here is a shot of the capture running.</p>
<p>http://codebutler.github.com/firesheep/tc12/#40</p>
<p>This will work with twitter, facebook, and google.</p>
<p>Anything that does not keep an SSL connection is in trouble.  So far it will support Windows and OSX but you need the PCAP libs installed for it to work.</p>
<p>Remember on Windows thats LibPCAP.</p>
<p>Enjoy!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/facebook-session-hijacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How much is too much with facebook?</title>
		<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/how-much-is-too-much-with-facebook/</link>
		<comments>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/how-much-is-too-much-with-facebook/#comments</comments>
		<pubDate>Tue, 26 Oct 2010 04:15:50 +0000</pubDate>
		<dc:creator>Dan O'Connor</dc:creator>
				<category><![CDATA[facebook]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/Irregular-Expressions/how-much-is-too-much-with-facebook/</guid>
		<description><![CDATA[Interesting note, applications can permit access to your &#8216;personal&#8217; information on facebook.  Not only your information directly, but if one of your friends has the application installed, it will have access to their friends data. Is that really something that users need? Not really. Now think of those scam / click jacking links on facebook, [...]]]></description>
				<content:encoded><![CDATA[<p>Interesting note, applications can permit access to your &#8216;personal&#8217; information on facebook.  Not only your information directly, but if one of your friends has the application installed, it will have access to their friends data.</p>
<p>Is that really something that users need?</p>
<p>Not really.</p>
<p>Now think of those scam / click jacking links on facebook, the average facebook user has 130 friends.  I just saw one of those click jacking links on my feed with 26,000 people liking it.</p>
<p>Think of the math, and this is only one!</p>
<p>26,000 x 130 = 3,380,000 profiles they now have access to!</p>
<p>Talk about gravy train of personal information, of course the best thing is not to put that type of stuff on to facebook.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/how-much-is-too-much-with-facebook/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>One more facebook thing</title>
		<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/one-more-facebook-thing/</link>
		<comments>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/one-more-facebook-thing/#comments</comments>
		<pubDate>Thu, 14 Oct 2010 00:10:55 +0000</pubDate>
		<dc:creator>Dan O'Connor</dc:creator>
				<category><![CDATA[facebook]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/Irregular-Expressions/?p=407</guid>
		<description><![CDATA[I have talked about creating fake facebook profiles to gather information from people. But I saw a couple things in the last two weeks that I thought was neat. http://www.networkworld.com/news/2010/091910-interpol-chief-has-facebook-identity.html That is too funny, it sounds like who ever did it was able to get access to information that they should not have. Again just [...]]]></description>
				<content:encoded><![CDATA[<p>I have talked about creating fake facebook profiles to gather information from people. But I saw a couple things in the last two weeks that I thought was neat.</p>
<p>http://www.networkworld.com/news/2010/091910-interpol-chief-has-facebook-identity.html</p>
<p>That is too funny, it sounds like who ever did it was able to get access to information that they should not have.  Again just like I mentioned before it was someone who was not on facebook that was used as the target.</p>
<p>The other thing I saw was a special on 20/20 on the movie Catfish,I don&#8217;t want to spoil the movie but they take it to another level.  The 20/20 bit is worth watching alone if you don&#8217;t want to go see a movie.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/one-more-facebook-thing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Some more stuff with facebook</title>
		<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/some-more-stuff-with-facebook/</link>
		<comments>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/some-more-stuff-with-facebook/#comments</comments>
		<pubDate>Wed, 13 Oct 2010 01:25:41 +0000</pubDate>
		<dc:creator>Dan O'Connor</dc:creator>
				<category><![CDATA[facebook]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/Irregular-Expressions/some-more-stuff-with-facebook/</guid>
		<description><![CDATA[A little older post from isc.sans.edu about more &#8216;like&#8217; stuff at facebook. http://isc.sans.edu/diary.html?storyid=9556 Not exactly the same as what I previously posted, but it&#8217;s something else to read. Sure can make facebook live up to it&#8217;s number two threat vector on the internet. I did find a little more that is related to my last [...]]]></description>
				<content:encoded><![CDATA[<p>A little older post from isc.sans.edu about more &#8216;like&#8217; stuff at facebook.</p>
<p>http://isc.sans.edu/diary.html?storyid=9556</p>
<p>Not exactly the same as what I previously posted, but it&#8217;s something else to read.</p>
<p>Sure can make facebook live up to it&#8217;s number two threat vector on the internet.</p>
<p>I did find a little more that is related to my last post, here is an article from sophos.  It&#8217;s not exactly the same but it uses a similar tactic to get users to click on the supplied link.</p>
<p>http://www.sophos.com/blogs/gc/g/2010/04/06/cheryl-cole-pictures-bait-facebook/</p>
<p>The choice of the age group of the targets this time is pretty clear, it should be pretty easy to get access to a lot of profiles.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/some-more-stuff-with-facebook/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Something is a miss with Java Script!</title>
		<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/something-is-a-miss-with-java-script/</link>
		<comments>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/something-is-a-miss-with-java-script/#comments</comments>
		<pubDate>Sun, 03 Oct 2010 05:21:58 +0000</pubDate>
		<dc:creator>Dan O'Connor</dc:creator>
				<category><![CDATA[exploits]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[java script]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/Irregular-Expressions/something-is-a-miss-with-java-script/</guid>
		<description><![CDATA[Something strange is going around the facebooks in the last couple days, I noticed a few people posting this &#8216;like&#8217; but did not pay much attention to it. http://mashable.com/2010/10/01/warning-facebook-like-worm-spreading-through-javascript-exploit/ The story says that it does not appear to do anything bad at this point, if that is the case you would think something would be [...]]]></description>
				<content:encoded><![CDATA[<p>Something strange is going around the facebooks in the last couple days, I noticed a few people posting this &#8216;like&#8217; but did not pay much attention to it.</p>
<p>http://mashable.com/2010/10/01/warning-facebook-like-worm-spreading-through-javascript-exploit/</p>
<p>The story says that it does not appear to do anything bad at this point, if that is the case you would think something would be following soon with payload before it gets patched.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/something-is-a-miss-with-java-script/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Excellent work up of a facebook vulnerability</title>
		<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/excellent-work-up-of-a-facebook-vulnerability/</link>
		<comments>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/excellent-work-up-of-a-facebook-vulnerability/#comments</comments>
		<pubDate>Sun, 18 Jul 2010 05:33:22 +0000</pubDate>
		<dc:creator>Dan O'Connor</dc:creator>
				<category><![CDATA[facebook]]></category>
		<category><![CDATA[facebook sql]]></category>
		<category><![CDATA[inj3ct0r]]></category>
		<category><![CDATA[inj3ct0r facebook]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/Irregular-Expressions/excellent-work-up-of-a-facebook-vulnerability/</guid>
		<description><![CDATA[The inj3ct0r team did a real good job with this write up, http://inj3ct0r.com/exploits/11638 In the next few days I will pull a few quotes out of it and try to expand a little more on whats going on. Enjoy!]]></description>
				<content:encoded><![CDATA[<p>The inj3ct0r team did a real good job with this write up,</p>
<p>http://inj3ct0r.com/exploits/11638</p>
<p>In the next few days I will pull a few quotes out of it and try to expand a little more on whats going on.</p>
<p>Enjoy!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/excellent-work-up-of-a-facebook-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
