iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > Insider Reports > Insider > Facebook Opened Its Source Code
Search:
[ insider_reports_insider ]

Facebook Opened Its Source Code



David Utter
Staff Writer
2007-08-13

SecurityProNews: Insider Reports Insider Reports RSS Feed


Anyone with a fascination for seeing a PHP-powered page make calls to a bunch of PHP scripts got an eyeful from social networking site Facebook over the weekend.

Facebook Opened Its Source Code
Facebook Opened Its Source Code

Facebook heatedly demanded the removal of its home page source code from a blog, Facebook Secrets, and any other sites that reproduced it over the weekend. Unsecured access to the code allowed people to grab a copy; given the nature of the Internet, plenty of people probably did so.

Nik Cubrilovic pointed out the code's availability in his post at TechCrunch. He cited an anonymous tip that the code had been leaked and reproduced on Facebook Secrets, where it could still be found early Monday morning.

Facebook representatives made a statement and echoed it in a comment on Cubrilovic's post regarding the leak. The official response:

A small fraction of the code that displays Facebook web pages was exposed to a small number of users due to a single misconfigured web server that was fixed immediately. It was not a security breach and did not compromise user data in any way. Because the code that was released only powers the Facebook user interface, it offers no useful insight into the inner workings of Facebook. The reprinting of this code violates several laws and we ask that people not distribute it further.

Cubrilovic noted on his personal blog how PHP sometimes sends back source code in response to a poorly processed request. He listed some ways of securing PHP better, like using mod_security with Apache, and a couple of httpd.conf tweaks to keep another site from making the same exposure Facebook did.



About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More insider_reports_insider Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds