LinkedIn exploit 'left millions exposed' to malware

Check Point research highlights now patched vulnerabilities in LinkedIn's messaging service

LinkedIn on a mobile device

Exploits in LinkedIn's own security measures potentially allowed hackers to spread malicious files across the social networking site and infect millions of user PCs, it has been claimed.

The Microsoft-owned professional networking site, that boasts over 500 million users in 200 countries, allows members to chat, share CVs and send job descriptions to others in their network using a messenger service.

Multiple vulnerabilities were identified in LinkedIn's own security measures that are designed to restrict the types of files that are uploaded to LinkedIn's chat windows, according to security researchers at Check Point.

Advertisement - Article continues below

Typically these measures allow only a handful of extensions including pdf, text documents and jpegs, however, it was discovered that attackers could bypass these checks by uploading malicious files masquerading as accepted extensions. These were then capable of spreading throughout a user's network of contacts and infect any PCs connecting to those accounts.

The research identified four exploits in the LinkedIn security systems, including a limitation that failed to identify a malicious Power Shell script that was saved as a .pdf, which if downloaded, would remain undetected on a user's PC.

How a link may have appeared in a user's chat window

The Power Shell script made to masquerade as a .pdf file

Advertisement
Advertisement - Article continues below

The system was also unable to detect malicious Excel XLSM macros, disguised with an accepted .xlsx extension, which when uploaded would bypass the antivirus checks and be sent unnoticed to a user.

These types of attacks meant hackers could infect a user's PC with whatever code they wished, potentially stealing personal information, encrypting data, or hijack a machine for the purpose of spreading malware to other PCs.

Advertisement - Article continues below

Although there is no evidence that the vulnerabilities had been noticed and exploited by hackers, it serves to highlight the importance of robust security measures on a site that allows its millions of users to share files with each other.

Check Point notified LinkedIn of the vulnerabilities earlier this year, and they have since been acknowledged and patched as of the 24 June.

Main image: Bigstock - body images courtesy of Check Point.

Featured Resources

Top 5 challenges of migrating applications to the cloud

Explore how VMware Cloud on AWS helps to address common cloud migration challenges

Download now

3 reasons why now is the time to rethink your network

Changing requirements call for new solutions

Download now

All-flash buyer’s guide

Tips for evaluating Solid-State Arrays

Download now

Enabling enterprise machine and deep learning with intelligent storage

The power of AI can only be realised through efficient and performant delivery of data

Download now
Advertisement

Recommended

Visit/security/malware/355093/evasive-malware-threats-are-surging
malware

Evasive malware threats doubled in 2019

24 Mar 2020
Visit/security/355013/10-quick-tips-to-identifying-phishing-emails
Security

10 quick tips to identifying phishing emails

16 Mar 2020
Visit/business-strategy/mergers-and-acquisitions/354941/panda-security-to-be-acquired-by-watchguard
mergers and acquisitions

Panda Security to be acquired by WatchGuard

9 Mar 2020
Visit/security/malware/28083/the-five-best-free-malware-removal-tools
Security

Best free malware removal tools 2019

2 Mar 2020

Most Popular

Visit/security/privacy/355155/zoom-kills-facebook-integration-after-data-transfer-backlash
privacy

Zoom kills Facebook integration after data transfer backlash

30 Mar 2020
Visit/infrastructure/server-storage/355118/hpe-warns-of-critical-bug-that-destroys-ssds-after-40000-hours
Server & storage

HPE warns of 'critical' bug that destroys SSDs after 40,000 hours

26 Mar 2020
Visit/software/355113/companies-offering-free-software-to-fight-covid-19
Software

These are the companies offering free software during the coronavirus crisis

25 Mar 2020
Visit/security/cyber-crime/355171/fbi-warns-of-zoom-bombing-hackers-amidst-coronavirus-usage-spike
cyber crime

FBI warns of ‘Zoom-bombing’ hackers amid coronavirus usage spike

31 Mar 2020