wasc-whid@lists.webappsec.org

WASC Web Hacking Incidents Database

View all threads

WHID 2011-35: 'Dating site' takes pictures and names of 250, 000 unsuspecting Facebook users

WW
WASC Web Hacking Incidents Database
Fri, Feb 4, 2011 3:46 PM

WHID 2011-35: 'Dating site' takes pictures and names of 250,000 unsuspecting
Facebook users

Entry Title: WHID 2011-35: 'Dating site' takes pictures and names of 250,000
unsuspecting Facebook users
WHID ID: 2011-35
Date Occurred: February 4, 2011
Attack Method: Process Automation
Application Weakness: Insufficient Anti-automation
Outcome: Disinformation
Attacked Entity Field: Web 2.0
Attacked Entity Geography: USA
Incident Description: Creators of a fake dating site have taken personal
information from 250,000 Facebook profiles - and reproduced it without the
knowledge of the members of the popular social networking site.
However, bosses at Facebook have hit out at the misuse of the information
held on their site and said they will 'take appropriate action'.
'Scraping people¹s information violates our terms. We have taken, and will
continue to take, aggressive legal action against organisations that violate
these terms,' Facebook¹s director of policy communications, Barry Schnitt,
told Wired.com.
Mass Attack: No
Reference:
http://www.dailymail.co.uk/news/article-1353643/Facebook-profiles-hacked-Dat
ing-site-lifts-250-000-pictures-names.html
Attack Source Geography:
Attacked System Technology: Facebook

WHID 2011-35: 'Dating site' takes pictures and names of 250,000 unsuspecting Facebook users Entry Title: WHID 2011-35: 'Dating site' takes pictures and names of 250,000 unsuspecting Facebook users WHID ID: 2011-35 Date Occurred: February 4, 2011 Attack Method: Process Automation Application Weakness: Insufficient Anti-automation Outcome: Disinformation Attacked Entity Field: Web 2.0 Attacked Entity Geography: USA Incident Description: Creators of a fake dating site have taken personal information from 250,000 Facebook profiles - and reproduced it without the knowledge of the members of the popular social networking site. However, bosses at Facebook have hit out at the misuse of the information held on their site and said they will 'take appropriate action'. 'Scraping people¹s information violates our terms. We have taken, and will continue to take, aggressive legal action against organisations that violate these terms,' Facebook¹s director of policy communications, Barry Schnitt, told Wired.com. Mass Attack: No Reference: http://www.dailymail.co.uk/news/article-1353643/Facebook-profiles-hacked-Dat ing-site-lifts-250-000-pictures-names.html Attack Source Geography: Attacked System Technology: Facebook