Categories
research security

Who On Earth Is ”Mr. Cypher“: Automated Friend Injection Attacks on Social Networking Sites

Abstract. Within this paper we present our novel friend injection attack which exploits the fact that the great majority of social networking sites fail to protect the communication between its users and their services. In a practical evaluation, on the basis of public wireless access points, we furthermore demonstrate the feasibility of our attack. The […]

Categories
random research security

Facebook: A security and privacy nightmare?

Apparently Facebook decided to open-up profiles to the public yet a little further in future, read more at this blog entry. So whilst a plethora of security research highlights how broken this service really is, Facebook keeps on exposing more private information to third-parties on a sneaky opt-out basis. Want to catch up how broken […]

Categories
ASE PASSAT-09 research security

Towards Automating Social Engineering Using Social Networking Sites (Preprint)

I made the preprint version of my publication on “Towards Automating Social Engineering Using Social Networking Sites” available online. You can fetch the pdf from here: http://asebot.nysos.net. As I said before I will present this work at this year’s PASSAT in Vancouver. Abstract—A growing number of people use social networking sites to foster social relationships […]