Noah's Randomness

Photographer, Traveler, Geek, Pentester, Information Security Consultant, Firefighter/EMT, etc…
  • rss
  • Home
  • My Resume
  • My Photos

Facebook Old Password vs Incorrect Password

Noah | December 26, 2011

So, I went to log into Facebook today, but typed in an incorrect password. Well, actually it was an old password. Facebook, in all its infinite wisdom, stated this – “Sorry! You entered an old password” as well as informed me when I last changed my password (click the image below to see the full-size version):

Now, when you enter a totally wrong/incorrect password, you get “Please re-enter your password” “The password you entered is not correct” (again, click the image below to see the full-size version):

Does anyone else see an issue with this? I know I do. Knowing human nature, people reuse passwords. So, now, from one single page, you have my email account AND knowledge of a password I’ve previously used. While the password may not work for Facebook, it probably would work somewhere else. The first place I would think to test it? Your email account. And what happens if I get access to your email account? Well, how do people usually get password resets? Ah, email! Bingo! :) So now I’ve got access to other accounts… and on and on and on.

It wouldn’t be too hard to automate testing Facebook passwords using a tool like Burp Intruder (http://portswigger.net/burp/intruder.html). Judging on the response sizes, you could determine whether A) You found a totally incorrect password B) You’ve found an old password, or C) You’ve successfully logged in/gained access to the FB account.

Now, this does not take into account any other protection mechanisms that Facebook might have in place, such as locking out an account after a series of invalid logon attempts, login approvals, etc.

Oh Facebook, you fail again…

Comments
2 Comments »
Categories
InfoSec
Comments rss Comments rss
Trackback Trackback

Categories

  • Bloomington Twp Fire Dept
  • Fire/EMS
  • How To
  • InfoSec
  • iPhone
  • Review
  • Uncategorized

What I'm Doing/My Tweets...

  • @claudijd Has anyone done a pipal or passpal analysis of the dump yet? I'd be interested in seeing the stats... 15 hrs ago
  • @jaredhamilton60 You're proud of that fact? Child please! 1 day ago
  • Anyone know of a good passphrase (14+ char) dictionary/wordlist for offline pw analysis? #infosec (cc: @hdmoore @distrrtgen @Bitweasil) 4 days ago
  • “@neiljaeh: @njaehner: Control, Alt, Delta?” <-- yep. Although today's airplane reboot is brought to you by US Airways 1 week ago
  • Boarded plane & told 35 minute delay due to maintenance. All systems just shut down/brought back up. Apparently reboots fix planes too #fb 1 week ago
  • More updates...

Posting tweet...

Powered by Twitter Tools

Google Voice

Ads:

Calendar

December 2011
M T W T F S S
« Aug   Jan »
 1234
567891011
12131415161718
19202122232425
262728293031  

Recent Comments

  • Noah Jaehnert (@njaehner) on Nest Learning Thermostat Unboxing/Install
  • Noah on Facebook Old Password vs Incorrect Password
  • Ariana on Facebook Old Password vs Incorrect Password
  • Noah on NeXpose and BackTrack 4: “Could not start the nxpgsql daemon” [Fixed]
  • TeNeX on NeXpose and BackTrack 4: “Could not start the nxpgsql daemon” [Fixed]

Akismet

5,139 spam comments blocked by
Akismet

Tags

awesome BackTrack Blackberry Blackberry Torch BTFD EMS Eye-Fi Fire Fire/EMS Fire Department fix funny gentoo How To Howto infosec iPhone NeXpose Passwords PixelPipe reddit Security Site Update Starbucks wordpress
rss Comments rss valid xhtml 1.1 design by jide powered by Wordpress get firefox