This Simple Hacks Allows Hackers To Listen to Your Facebook Messenger Voice Messages
Both FB Messenger and Facebook-owned WhatsApp allow users to send voice messages using the Mic icon in the chat bar. While many don’t use the Facebook Messenger voice message feature, it is still very popular. But next time you send a voice message to your near and dear ones or a business colleague, do remember that your voice chat can be snooped on by potential hackers thanks to a Man-in-the-Middle (MiTM) vulnerability.The Hacker News reports that an Egyptian security researcher Mohamed A. Baset has found a vulnerability in Facebook Messenger’s audio clip recording feature that allows any wannabe hacker to listen in to the message. The FB Messenger flaw allows any hacker to conduct a MiTM attack and grab your audio clip files from Facebook’s server.
How does a Hacker listen to your Facebook voice message?
The Facebook Messenger voice chat flaw is so simple that a hacker with minimum technical skill can exploit it. Whenever a person records an audio clip and sends it to some other person, the clip is uploaded to Facebook’s CDN server for example https://z-1-cdn.fbsbx.com/…, from where it serves the same audio file, over HTTPS, to both the sender as well as the receiver.Then, the attacker downgrades those absolute links from HTTPS to HTTP, allowing the attacker to direct download those audio files without any authentication.
Here’s a proof-of-concept video of the Facebook voice messages CDN hack:
Facebook Has Still Not Patched This Bug
Though the FB voice chat vulnerability looks critical, Facebook is yet to patch it. Baset has informed Facebook security engineers about the vulnerability long back. While Facebook engineers have acknowledged the bug, it didn’t offer any bug bounty to Baset neither has it patched the bug. “The fact that we have not rolled it (HSTS) out on particular subdomains does not constitute a valid report under our program,” the company said.We have contacted Facebook security team for the comments on this vulnerbility and will update the artice accordingly.
No comments:
Post a Comment