Facebook
Facebook claims that a recent source code leak does not represent a security breach

Facebook lets source code slip

Misconfigured web server leaves site red-faced

Written by Ian Williams

A portion of the source code for social networking site Facebook was inadvertently made available recently because of an incorrectly configured web server hosting the code.

A copy of the code was posted on the Facebook Secrets blog which appears to have been created specifically to post the code.

"A small fraction of the code that displays Facebook web pages was exposed to a small number of users due to a single misconfigured web server that was fixed immediately," said Brandee Barker, a spokeswoman for Facebook.

"It was not a security breach and did not compromise user data in any way. Because the code only powers the Facebook user interface, it offers no useful insight into the inner workings of Facebook."

The leak comes just weeks after the site's founder had to defend himself against allegations that he stole the source code source from fellow university students.

The problem appeared when the page showed the un-interpreted source code for the main index page rather than returning the standard output.

The problem has been put down to a server misconfiguration, or a known bug in the Apache server which may occur when the server experiences high loads.

Despite Facebook's assertions that there are no security issues surrounding the leak, security experts have warned that access to the application source code is always useful to hackers looking to subvert or compromise a website.

"Anytime that source code is accidentally revealed, there is potential for an increase in risk," said Pete Lindstrom, a senior security analyst at Burton Group.

He added that when a company dismisses the security implications of such an incident, there are likely to be real security issues.

"There are enough folks out there trolling the websites who will be perfectly happy to try to identify vulnerable areas that could be exploited," said Lindstrom.

"If you release source code into the wild, you are going to have some level of increased risk associated with it. I cannot think of a case where you would not."

Tags:

Further reading

Facebook theft case gets underway

Lawsuit alleges breach of contract, copyright infringement and fraud   More...

IMDb loses advertisers over adult listings

National Lottery and Barclaycard pull out over porn links   More...

Facebook adds ad hoc ad-block

UK advertisers can choose where their brands don't appear   More...

Facebook worth $6bn claims analyst

Yahoo could still bag the site if it's willing to stump up the cash   More...

Related articles

ConnectU given two weeks to prove Facebook case

Dorm room chat doesn't make a commercial contract, says judge   More...

Facebook theft case gets underway

Lawsuit alleges breach of contract, copyright infringement and fraud   More...

Poor Citrix set-ups leave firms vulnerable

Security firm claims many organisation fail to install Citrix correctly   More...

Trend Micro plugs leaks with Provilla buy

Provilla will operate as a subsidiary of Trend Micro's US affiliate   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

09 May 2008

2.51 MBWiMax muddle, Google tactics and asteroid bunkum More...

08 May 2008

3.26 MBBroadband Anywhere, phone-free transport and Web 3.0 More...

07 May 2008

3.19 MBUK success, a paucity of IT women and robot wars More...

Poll

DATA ENCRYPTION

DATA ENCRYPTION

Should encryption be mandatory for all personal data held by companies and governments?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Ofcom

Ofcom outlines future wireless vision

Wi-Fi healthcare and intelligent car brakes in the pipeline   More...

HP

HP Labs opens doors to academia

Innovation Research Program invites proposals related to current research   More...

Advertisement

Asteroid

Nasa plans manned mission to asteroid

Bruce Willis thankfully not going   More...

MySpace

MySpace offers opt-in data sharing

Deals signed with Photobucket, Twitter, eBay and Yahoo   More...

Advertisement