Buffer overflows were at the heart of a series of recent hacks against the Facebook and MySpace social networking sites.
That’s the verdict of application vulnerability specialist Fortify Software, which says that a buffer overflow enabled hackers to exploit the Aurigma ActiveX image uploading software used by these two – and other – social networking sites.
“The bad news is that this exploit is being used in a hacker toolkit currently being offered for download on several Chinese language hacker sites – meaning that novices have been able to stage these attacks, and not just professional hackers,” says Fortify marketing director Rob Rachwald.