Facebook Connect being hijacked by China's Great Firewall

Status
Not open for further replies.

Ink

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
For the last three days, China's Great Firewall has been intercepting the Javascript module from Facebook's login feature, Facebook Connect, which allows third-party sites to authorize users through their Facebook login. First reported on Sunday, the attack causes sites using Facebook Connect to redirect to a third-party page. Readers have confirmed to The Verge that the redirection attack is still under way, and sites using Facebook Connect are automatically redirecting when accessed without a VPN or a Javascript blocker. Local media in Beijing has also reported on the problem. Facebook did not immediately respond to a request for comment.

Facebook Connect communicates login information from Facebook, allowing a Facebook login to extend to third party sites through a Javascript applet. The applet is enabled on thousands of sites across the web, including The Verge. On Sunday, the Great Firewall started intercepting that applet in transit and replacing it with a new single-line redirection code from two third-party sites. The result is that, for non-VPN users in China, any page with a Facebook Connect button has been redirecting to two sites: wpkg.org or ptraveler.com, an open-source software project and a personal travel blog respectively. It's unclear why the Chinese government would want to send users to these sites, although ptraveler.com seems to have been brought down by the flood of traffic.

Read more: http://www.theverge.com/2015/4/28/8508117/facebook-connect-great-firewall-great-cannon-censorship
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top