The Hacker News

on Thursday, 5 September 2013
 

 

The Hacker News
The Hacker News has been internationally recognized as a leading news source dedicated to promoting awareness for security experts and hackers // via fulltextrssfeed.com

Hacking Facebook to delete any account; Facebook again refuses to pay Bounty
9/5/2013 2:15:00 PM

In the past few days, Facebook refused to pay bounty to Khalil Shreateh, the security researcher who used the bug he discovered to post directly on Facebook CEO Mark Zuckerberg's Timeline after Facebook Security rejected his attempts to report it.

Ehraz Ahmed, an independent Security Researcher claimed that he reported a critical vulnerability to the Facebook Security team, which allows the attacker to delete any account from Facebook.

But Facebook refuses to Pay Bug Bounty, because he tested flaw once on his friend's account, "I reported this bug to Facebook, I'm really not happy with them. After waiting for such a long time for their reply, they denied it saying that you used this bug only works for test accounts, where as I used it for removing real accounts and now the vulnerability is also fixed after their email." he said on his blog.

Video Demonstration of Exploit:


Vulnerable URL:

https://www.facebook.com/ajax/whitehat/delete_test_users.php? fb_dtsg=AQA1E-WE&selected_users[0]=[Victems Profile ID]&__user=[Attackers Profile ID]&__a=1

Where selected_users[0] and __user parameters are vulnerable to run exploit. Using the flaw hacker was also able to delete Facebook CEO Mark Zuckerberg's profile. For now the vulnerability is fixed by the Facebook team. But Should these Bug Hunters now stop reporting to vendors and start selling exploits again in underground hacking forums ?

Just four days before Facebook fixed another flaw that allowed hackers to delete photos of any user.

Latest Hacking News Updates

Author details

photo of Mohit Kumar

aka 'Unix Root' is Founder and Editor-in-chief of 'The Hacker News'. He is a Security Researcher and Analyst, with experience in various aspects of Information Security. Other than this : He is an Internet Activist, Strong supporter of Anonymous & Wikileaks. Follow him @ Twitter | LinkedIn | | | Facebook Profile

 

You are receiving this email because you subscribed to this feed at feedmyinbox.com

If you no longer wish to receive these emails, you can unsubscribe from this feed, or manage all your subscriptions

0 comments:

Post a Comment