A hacker may have done the Facebook world a favour by cracking the social network’s CEO and founder Mark Zuckerberg’s fan page. The posting of an unofficial status comment to the page shows the vulnerability of the simple plain text password system and such a high profile exploit may spur some action.

It is not known whether the hacker merely guessed the user name and password, brute forced the access using a dictionary attack or actually found a vulnerability to bypass the security system.

No Comment From The Z-man

Facebook has yet to comment on the circumstances of this attack, and of the recent similar attack on the page of Nicolas Sarkozy, the French president. But the Zuckerberg page has now been withdrawn.

The hacker posted the following message:

“Let the hacking begin: If Facebook needs money, instead of going to the banks, why doesn’t Facebook let its users invest in Facebook in a social way? Why not transform Facebook into a ‘social business’ the way Nobel Prize winner Muhammad Yunus described it? What do you think? #hackercup2011”.

The #hackercup2011 tag could indicate that it was the work of a would-be prize-winner in a current Facebook hacking competition.

As with a January 8 spoof news story about Facebook closing down in March, many people were taken in by the posting, despite the hacker effectively signing his or her work. Before the page was taken down by company officials, over 1,800 Facebookers had hit the “Like” button and more than 500 people had added Comments.

Graham Cluley, senior technology consultant at Sophos, has said that 2011 will be the year when social network security, or lack of it, comes to the fore as an issue. He told eWEEK Europe, that it may not be entirely Zuckerberg’s fault. “It’s possible that his fan page is administered by a cohort of minions, rather than just the Z-man himself,” he said.

He moved on to say that, despite details of the hack not being available, it underlines some basic principles. Passwords should be devised that are difficult to guess and not shared with others, and free Wi-Fi services – which are more widely available in the US, but available here at hotels and outlets like Starbucks – should be treated with caution.

“If you’re accessing the Internet via free Wi-Fi (think Starbucks) then either ensure it is encrypted or set up an https connection to avoid the threat of sidejacking by the likes of Firesheep. If [a hack attack] can happen to a high profile page like Zuckerberg’s – none of us are immune,” Cluley said.

Eric Doyle, ChannelBiz

Eric is a veteran British tech journalist, currently editing ChannelBiz for NetMediaEurope. With expertise in security, the channel, and Britain's startup culture, through his TechBritannia initiative

Recent Posts

TSMC Denies Talks With Intel Over Chipmaking Joint Venture

Denial from TSMC, after multiple reports it was in talks with Intel over a joint…

3 days ago

Apple iPhone Shipments In China Slide, As Cook Talks With Trump Official

CEO Tim Cook talks to Trump official, as IDC notes China's smartphone market growth, and…

3 days ago

AMD Warns Of $800m Charge From US Chip Restrictions On China

Another big name chip maker expects a hefty financial charge, after the US tightened rules…

3 days ago

Google Digital Ad Network Ruled Illegal Monopoly By Judge

More bad news for Google. Second time in less than a year that some part…

3 days ago

US State Dept Closes Office Flagging Russia, China Disinformation

Federal office that tackled misinformation and disinformation from hostile nations is closed down, after criticism…

4 days ago

Nvidia CEO Jensen Huang Makes Surprise Visit To China

After Nvidia admits it will take $5.5 billion charge as Trump export limits of slower…

4 days ago