Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
Check out the brand new SourceForge HTML5 speed test! Test your internet connection now. Works on all devices. ×
Facebook

Submission + - Researcher Finds Serious Password Reset Hole In Accellion Secure FTP (securityledger.com)

chicksdaddy writes: "A security researcher who was looking for vulnerabilities in Facebook’s platform instead stumbled on a much larger hole that could affect scores of firms who rely on a secure file transfer platform from Accellion, The Security Ledger reports.

Writing on his blog on Monday, Israeli researcher Nir Goldshlager said he discovered the password reset vulnerability while analyzing a Accellion deployment that is used, internally, by Facebook employees. Goldshlager used public knowledge of the Accellion platform to access a hidden account creation page for the Facebook deployment and create a new Facebook/Accellion account linked to his e-mail address.

After analyzing Accellion's password reset feature, he realized that — with that valid account — he could reset the password of any other Facebook/Accellion user with some cutting and pasting and a simple HTTP POST request, provided he knew the user's login e-mail address — effectively hijacking the account.

Goldshlager said he informed Facebook and that the hole has been patched by Facebook and Accellion. However, other Accellion customers using private cloud deployments of the product could still be vulnerable."

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.

Researcher Finds Serious Password Reset Hole In Accellion Secure FTP

Comments Filter:

How long does it take a DEC field service engineer to change a lightbulb? It depends on how many bad ones he brought with him.

Working...