What's new

Indian engineer gets $12,500 bounty for finding a Facebook bug

Splurgenxs

SENIOR MEMBER
Joined
Mar 24, 2011
Messages
2,512
Reaction score
0
Country
India
Location
India
Facebook had a security bug that could be exploited to delete any image on the social networking site posted by anyone, without the original poster's knowledge and approval.

Interestingly, an Indian electronics and communications engineer, Arul Kumar, discovered this vulnerability and shared it with Facebook under its Whitehat bug reporting program, winning a $12,500 bounty in the process.

The 21-year old engineer from Tamil Nadu, discovered that the mobile version of Facebook's Support Dashboard, which allows users to flag and report a picture for removal, could be exploited to remove any photograph posted by any Facebook user.

When a user sends a photo removal request through the Support Dashboard, usually Facebook takes a look and decides if it should be removed or not. If Facebook decides not to remove it, then the user has the option of sending a message to the user who has posted the picture with a request to remove the same picture. The request also contains a link, clicking on which leads to the removal of the photo.

Kumar discovered that while sending a removal request, a user can manually modify the Photo_id and the photo owner's Profile_id parameters, following which the photo removal link can be sent to one's own Facebook ID and used to delete the photo without the original uploader's knowledge. Using the same method, any picture on Facebook could be deleted without the involvement of the user who originally posted the picture.

As per Kumar, the same exploit could have been used for removing photos posted by even verified users, fan pages and groups and from status updates, photo albums, suggested posts and comments.
When Kumar first shared the vulnerability with Facebook, it was dismissed, with the Facebook security team unable to delete any pictures through the suggested hack. Following this, Kumar sent Facebook a proof of concept video demonstrating the bug through a dummy account. The second attempt was fruitful and the Facebook security team was able to see the vulnerability.

Indian engineer gets $12,500 bounty for finding a Facebook bug that let anyone delete pictures | NDTV Gadgets

Thats a good payoff.
 
Facebook is a crap company which just got lucky.

Google, on the other hand, has developed some seriously cutting edge technology.
 
Not under my real name, and I put nothing remotely personal on FB.
FB is a goldmine for identity thieves and other criminals.

then u are a hypocrite critising facebook.....it was a trick question:sniper:
 
then u are a hypocrite critising facebook.....it was a trick question:sniper:

Not at all.
I was talking about the technology behind facebook, which is nothing ground breaking, unlike google.
 
Not at all.
I was talking about the technology behind facebook, which is nothing ground breaking, unlike google.

Facebook may not be ground breaking but it appealed to the masses. That's the most important thing. Same goes with windows, It may not be the best but people feel more comfortable using it.
 
Not at all.
I was talking about the technology behind facebook, which is nothing ground breaking, unlike google.

when games like Candy crush make more than lets say , ummm, 'Fez' (one of the best inde retro performers ive played) one relly isn't in for technological superiority anymore.
Google tho is on a league of its own when it comes to innovating,
nevertheless its all about taping that niche nowadays...get rich quick.And Facebook made it luck or not.
 
nevertheless its all about taping that niche nowadays...get rich quick.And Facebook made it luck or not.

Agreed. Cutting edge technology is only relevant in a small segment of almost any market.

Both google and facebook are breaking new ground in terms of total number of users, including simultaneous users.

Google needs to stay innovative to keep providing added value to consumers, but facebook is in a place where they can squeeze out more value from existing technology.
 

Latest posts

Back
Top Bottom