• On TechRepublic: 10 cool USB flash drive tricks
September 19, 2008 4:35 PM PDT

Hole unveils Facebook fan pages

by Elinor Mills

A new hole in Facebook allows members to see the fan pages of people on the networking site who they aren't friends with, an outside researcher revealed on Friday.

In verifying the hole, CNET News--signing onto the site as someone who is not a designated "friend" of Facebook founder Mark Zuckerberg--was still able to see that he is a fan of Barack Obama, the Dalai Lama, Green Day, Nirvana, Central Park, the Monterey Bay Aquarium, and Apple Students.

All a would-be spy has to do is go to anyone's profile page, click on the "Info" tab and hover the mouse over the "see all" hot link at the top right of the list of fan pages. The URL for the fan pages appears at the bottom of the Web page and can be cut and pasted into a new window. Replacing the serial number of the user in the URL with the serial number of a target user (which anyone can find) will then take you to that user's fan page.

"It's a simple logic error," said Byron Ng, a Vancouver, Canada-based computer technician whose hobby is researching holes in social networks and other sites.

A Facebook spokesman said the company would look into the bug.

"By becoming a fan of a page, users have chosen to publicly affiliate themselves with the brand, band, cause, or figure represented by the page," the spokesman said in a statement via e-mail. "We're concerned with any behavior that users may not anticipate, even when it involves public information, and we are currently evaluating this bug."

For instance, Zuckerberg is publicly listed among the fans of the Barack Obama page, but someone would normally have to look for him on all the fan pages on the site in order to compile comprehensive list like the one displayed on his profile page.

Testing a new vulnerability, CNET News was able to see this private page showing the entire list of restaurants, politicians, and musicians that Facebook founder Mark Zuckerberg is a fan of.

(Credit: Facebook)

Earlier this week Facebook fixed a vulnerability that allowed people to see the photos of Facebook members they weren't friends with through the mobile site.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
advertisement
Click here!
Recent posts from Security
Microsoft to fix holes in Windows, Office
Google privacy controls: Most people won't care
Zero-day flaw found in Web encryption
Mac Game: Art project or malware?
Corporate bank accounts targeted in online fraud
Hacker breaks into jailbroken iPhones, asks for $7
Malwarebytes accuses rival of software theft
Security firm M86 acquires Finjan
Add a Comment (Log in or register) (5 Comments)
  • prev
  • 1
  • next
by ronjay September 19, 2008 5:08 PM PDT
Oh wow. Nobody really cares! Now I understand why C|Net gets so much criticism about the things they post as "news".
Reply to this comment
by timber2005 September 19, 2008 5:42 PM PDT
Argh... I wish some days that Facebook would go back TWO versions...
Schools only, no fan pages, no applications, no chat.
Reply to this comment
by xtrasico September 20, 2008 6:20 AM PDT
Agreed! I dumped my Facebook account exactly because of that. Now it has SO MANY appz that you can't navigate easily on a friend's page.

On the other hand, right now I am investigating some illegal transactions made on a PC, and I know the user is going to wish there was no chat on Facebook. I got the logs because every message is stored as a web page. ;) Some people are just dumb.
by M C September 22, 2008 10:53 AM PDT
Yeah CNet! Digging for the important stories! What's next - "Telling friends your password can result in them logging on to your account"? I'm sure you can find a few publicity-hungry security "experts" that will offer up free quotes for that...
Reply to this comment
by phigma September 22, 2008 10:59 AM PDT
wow, terrible article. These aren't loopholes or vulnerabilities, these are very logical features.
Reply to this comment
(5 Comments)
  • prev
  • 1
  • next

FAQ: Buying the right Windows 7 upgrade

Readers still have lots of questions on just which version of the software they need to buy in order to upgrade their PC. CNET News tries to offer some answers.

N.Y. lawsuit details Intel's 'largesse' toward Dell

Attorney General Andrew Cuomo's federal antitrust case filed Wednesday alleges a longstanding symbiotic relationship between Intel and Dell.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right