Huge LinkedIn loophole put user security at risk

  发布时间:2024-09-22 05:42:24   作者:玩站小弟   我要评论
If you were browsing the LinkedIn job boards this morning, you could have come across a job opening 。

If you were browsing the LinkedIn job boards this morning, you could have come across a job opening from Mashable titled “Assistant to Matt Binder.”

Mashable ImageIt's true. It would be the best job in the world...if it actually existed.Credit: Screenshot: matt binder / mashable

Even though it appears right there on Mashable’s official LinkedIn business page, the company, unfortunately, is not hiring me an assistant. Mashable’s human resources department did not post that job listing. No one at the company posted the opening. The job does not exist.

So, how did it show up alongside the company’s very real, official job posts?

Mashable ImageOne of these Mashable job openings is not like the others.Credit: screenshot: matt binder / mashable

Michel Rijnders, an online recruiter from the Netherlands with absolutely no connection to Mashable, posted it. (The job listing has since been taken down.)

Rijnders discovereda serious flaw embedded within a very basic LinkedIn feature that allows users to post an official looking job opening on nearly any company’s LinkedIn business page. These unofficial listings show up on a company’s “Jobs” page and look just like any other job opening posted legitimately by the organization.

Earlier, Rijnders created job posts for a new Chief Executive Officer for LinkedIn and Google, something he very much has zero authority to do. Both fake listings appeared on the tech giants’ LinkedIn business pages alongside their other job openings. The listings also appeared in LinkedIn’s job search. There was no approval process required.

While LinkedIn does usually charge for posting a job listing, Rijnders, a premium LinkedIn subscriber, says he has been able to list each job opening for free.

Google, which scrapes hirings from recruitment websites all over the internet, aggregated the fake opening for its CEO position to its own job platform. Sorry, actual Google CEO Sundar Pichai.

Mashable Light SpeedWant more out-of-this world tech, space and science stories?Sign up for Mashable's weekly Light Speed newsletter.By signing up you agree to our Terms of Use and Privacy Policy.Thanks for signing up!

Rijnders was even able to take LinkedIn users offsite by linking his own business’ website to the “Apply” button on the job listing.

It’s easy to see how a scammer could use these fake but official-looking listings, aggregated all over the web to other trusted sources who also believe the listings to be official, for nefarious means. People hand over a lot of personal data when applying for a job.

In fact, one notable offender, a job-scraping site called Jooble, is what tipped off Rijnders to the problem to begin with.

“For a while I noticed scrapers, like Jooble, posting massive amounts of jobs at companies on LinkedIn without consent of those companies,” wrote Rijnders in an email to Mashable. “A lot of companies complained without any result. The bad thing is [the scrapers] collect the application details of applicants who think they actually apply at the company. These companies also seem to only pick smaller companies to do this with less risk of getting into trouble.”

Other LinkedIn users repliedto Rijnders’ LinkedIn post saying that they’ve brought up this problem to the company before.

SEE ALSO:LinkedIn is full of spies

“Because LinkedIn didn't really seem to see this as a problem, I used the same loophole to make the problem a bit more clear and urgent to them,” he explained. “That worked.”

LinkedIn is now apparently aware of the issue.

“Thank you, Michel Rijnders, for bringing this to our attention,” wrote LinkedIn’s head of trust and safety, Paul Rockwell, in a commentunder Rijnders’ post. “We've removed the posting and we're resolving the issue that allowed this post to go live.”

“LinkedIn is a place for real people to have real conversations about their careers. It's not a place for fake jobs,” Rockwell continued. “Posting jobs without explicit permission or knowledge of another party is against our Terms of Service. We are committed to stopping fraudulent jobs from ever reaching our members through automated technology and the help of our members reporting any suspicious job postings.”

While Rijnders confirms that his fake LinkedIn and Google listings were removed by the company, he was still able to exploit the flaw to create a Mashable listing more than 24 hours after publishing his post.

UPDATE: July 26, 2019, 5:01 p.m. EDT In addition to the earlier comment from LinkedIn's head of trust and safety, Paul Rockwell, a company spokesperson sent us the following statement:

This issue was caused by a bug in our online jobs experience that allowed members to edit the company after a job had already been posted. The issue has now been resolved.

Fraudulent job postings are a clear violation of our Terms of Service. When they are brought to our attention, we quickly move to take them down.

While we do allow companies to post on behalf of other companies (such as in the case of recruiting firms), this is only permitted with the knowledge of both parties.

Regarding free job postings, we have not historically had free job postings as part of the LinkedIn experience. However, we’re running a test that allows small and medium sized businesses to post a limited number of jobs for free. This member was a part of that test.


Featured Video For You
Google Nest camera security flaw allows former owners to observe others' homes

TopicsLinkedInSocial Media

  • Tag:

相关文章

  • 18 Slightly Submerged Architectural Wonders

    Across the globe, in lakes and oceans and other waterlogged enclaves there are works made by human h
    2024-09-22
  • Moon to meet with Seoul

    President Moon Jae-in will meet with Seoul-based foreign diplomats next week in an effort to seek co
    2024-09-22
  • The Thursday Slatest newsletter.

    Today’s biggest stories:A Doctors Without Borders-supported hospital in the already desperate city o
    2024-09-22
  • 获官方表彰!国联水产集团以“冠军品质”助力第19届亚运会

    获官方表彰!国联水产集团以“冠军品质”助力第19届亚运会_南方+_南方plus近日,国联水产集团收到杭州第19届亚运会官方回函,特此表彰其作为本届亚运会官方供应商对餐饮服务做出的贡献。亚运会期间,国联
    2024-09-22
  • 'Metaphor: ReFantazio' hands

    By the time I tapped out of Persona 5after 60 hours of a massive high school adventure that I was en
    2024-09-22
  • 抓重点防控构建和谐平安校园

    雅安日报讯4月9日下午,荥经县教育局组织召开干部职工集中学法暨义务教育均衡发展市级评估情况通报会,进一步加强机关干部职工及校(园)长法制教育,提高该县教育工作者学法的针对性和实效性。会议就新《安全生产
    2024-09-22

最新评论