Skip the navigation
News

Hundreds of Facebook groups 'hijacked'

Caper intended to highlight vulnerabilities on social networking sites, group says

By Jaikumar Vijayan
November 10, 2009 03:07 PM ET

Computerworld - An anonymous group calling itself "Control Your Info" has taken over hundreds of Facebook groups to highlight what it claims is a major security weakness on the social networking site.

Facebook downplayed the incident and said no hacking or confidential information was involved.

As of this morning, more than 200 Facebook groups had been hijacked and renamed Control Your Info. Pasted on each group's Wall was a message announcing that it had been "hijacked" and reminding members to be careful about controlling personal information on social networking sites.

"This means we control a certain part of the information about you on Facebook. If we wanted we could make you appear in a bad way which could damage your image," the message said.

"For example we could rename your group and call it something very inappropriate and nasty, like 'I support pedophile's rights,' " the message said, while going on to assure group members that Control Your Info wouldn't do that. The message also promised to restore each hijacked group's name by the "end of next week" and promised not to "mess anything up."

A separate Web site set up by Control Your Info claimed that the group's action did not constitute hacking but was a demonstration of how a legitimately available feature on Facebook can be used to easily hijack Facebook groups.

According to Control Your Info, when the administrator of a Facebook group leaves, anyone can register as a new administrator for that group. To take control of a Facebook group, a user only has to do a quick search on Google to identify public groups with no administrators.

Once someone signs up as a group administrator, that person then can do what it likes with the group, including changing its name, sending e-mails to members and editing information on it.

"This is just one example that really shows the vulnerabilities of social media. If you chose to express yourself on the internet, make sure the expressions are your own," the group urged.

In an e-mailed statement, a Facebook spokesman downplayed the incident and said there had been no hacking and no confidential information was at risk.

"The groups in question have been abandoned by their previous owners, which means any group member has the option to make themselves an administrator in order to continue communication to the group," the spokesman said.

The spokesman further stated that Facebook group administrators have no access to confidential information. Administrators can edit a group name, moderate discussions or send a message to members only in the case of small groups, the spokesman said. "The names of large groups cannot be changed, nor can anyone message all members," he said. In cases where Facebook finds that a group name has been changed inappropriately, it will disable those groups, which is what it plans on doing in this case, he said.

Read more about Security in Computerworld's Security Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
Identity Governance: The Business Imperatives
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make...
All Security White Papers
Security Webcasts
Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
Introduction to VMware vCenter Site Recovery Manager 5
Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
The Top Ten Secrets to Avoiding SAN Performance Problems
Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
Deduplication Without Compromise
Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
Director of Disk Products Discusses DXi6700
Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs