IT security firm asks hackers to steal your Facebook log-in
Sakurity's Reconnect tool lets cyber criminals hack Facebook accounts on Mashable, Booking.com, and Vimeo

An IT security firm has called on black hat hackers to break into user accounts on websites using Facebook log-ins.
Sakurity's appeal to cyber criminals was born of frustration with the social network, after the site failed to fix the vulnerability Sakurity notified it of a year ago.
The penetration testing firm has now released Reconnect, a tool that lets hackers target websites like Booking.com, Bit.ly, Mashable.com and Vimeo.
Founder Egor Homakov wrote: "Facebook refused to fix this issue one year ago, unfortunately it's time to take it to the next level and give blackhats this simple tool."
There's even an easy to follow guide to help cyber criminals use the tool, telling hackers exactly how to breach these sites' security protocols, presumably in a bid to encourage Facebook to resolve the issue more quickly.
Reconnect works by logging a user into a cyber criminal's Facebook account, and linking the user's account to the hacker's, giving the latter control over the user.
Criminals can start by pasting a Facebook log-out command URL into a web browser, then creating a Canvas application designed to log their victim into their own account.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Canvas applications are web pages loaded within Facebook (i.e. when you click on a link and it brings you to the desired external page, but you still see Facebook's blue borders surrounding the content).
This Canvas application will try and log the user in on the user's account, but Sakurity shows how to redirect that in order to log the user into the hacker's account.
Once that's done, the hacker has direct access to the user's account details, and can "change email/password, cancel bookings, read private messages and so on".
Ken Westin, security researcher at Tripwire, has tested the tool, calling it the real deal.
"I tested this out and it looks legitimate," he said. "This is a phisher's dream really, I am sure we will see a lot of Facebook accounts compromised by this."
But he warned that the threat is even graver when a user relies on the Firefox web browser.
"If a user is logged into Facebook and uses it to log into sites like Mashable or other services, and then clicks on a link that has been created using this vulnerability, an attacker can associate the account with the their Facebook account," he explained.
"The attacker can then log into the victim's Mashable account using stolen Facebook credentials. The user still has to click on a link in order for this to happen and, from what I can tell, also needs to be logged into Facebook."
While Sakurity founder Homakov claimed Facebook had refused to fix this issue a year ago, IT Pro understands this not to be the case.
Further, the social network is exploring the use of automated tools to sniff out and block these kind of hacks, and has contacted hundreds of developers suggesting they change to Facebook's log-in authentication measures, based on the OAuth 2.0 protocol, which would prevent this problem.
A spokesperson for Facebook told IT Pro: "This is a well-understood behaviour. Site developers using Login can prevent this issue by following our best practices and using the state' parameter we provide for OAuth Login.
"We've also implemented several changes to help prevent login Cross-Site Request Forgery and are evaluating others while aiming to preserve necessary functionality for a large number of sites that rely upon Facebook Login."
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
Latest Meta GDPR fine brings 12-month total to more than €1 billion
News Meta was issued with two hefty GDPR fines for “forcing” users to consent to data processing
By Ross Kelly
-
"Unacceptable" data scraping lands Meta a £228m data protection fine
News The much-awaited decision follows the scraping of half a billion users' data and received unanimous approval from EU regulators
By Rory Bathgate
-
Meta notifies around 1 million Facebook users of potential compromise through malicious apps
News The vast majority of apps targeting iOS users appeared to be genuine apps for managing business functions such as advertising and analytics
By Connor Jones
-
Facebook business accounts hijacked by infostealer malware campaign
News Threat actors are using LinkedIn phishing to seize business, ad accounts for financial gain
By Rory Bathgate
-
Meta begins encrypting Facebook URLs, nullifying tracking countermeasures
News The move has made URL stripping impossible but will improve analytics
By Rory Bathgate
-
Meta hit with €17 million fine over multiple GDPR breaches
News The social media giant set aside over €1 billion in November to help it cope with potential fines arising from data protection investigations
By Zach Marzouk
-
Meta says Apple's iOS privacy changes will cost it $10 billion in 2022
News The company's CFO suggests Google "faces a different set of restrictions" because it pays Apple to remain the default iOS search engine
By Bobby Hellard
-
Google, Facebook fined €210 million for making it difficult for users to reject cookies
News Data regulator CNIL gives companies three months to provide a system for refusing cookies that is as easy as single click consent
By Zach Marzouk