TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Delete any Photo from Facebook by Exploiting Support Dashboard

114 pointsby costapopescuover 11 years ago

8 comments

kristofferRover 11 years ago
This guy was lucky to be proficient enough in English to recieve the bounty, unlike this guy: <a href="http://www.theverge.com/2013/8/18/4633046/facebook-security-bug-let-anyone-post-on-walls" rel="nofollow">http:&#x2F;&#x2F;www.theverge.com&#x2F;2013&#x2F;8&#x2F;18&#x2F;4633046&#x2F;facebook-security-...</a>
评论 #6316077 未加载
评论 #6315760 未加载
评论 #6317183 未加载
lifeformedover 11 years ago
Facebook should make a &quot;Hack Me&quot; profile for people to mess with, so they don&#x27;t have to use Zuckerberg&#x27;s instead.
评论 #6315884 未加载
singoldover 11 years ago
Maybe now we can delete our own facebook photos...
pearjuiceover 11 years ago
Is it still worth it to follow every link on Facebook and check the URLs&#x2F;AJAX requests whether the parameters can be tampered with? At Facebook&#x27;s scale I always assumed there would be someone full-time employed to do this. In fact, I wouldn&#x27;t mind if it was good paying. Just give me all the Facebook frontend endpoints and I will go by them one-by-one. Manually. I will even document the test cases and what could be intercepted, changed or can be improved in terms of validation.
评论 #6317412 未加载
locengover 11 years ago
Facebook really doesn&#x27;t test anything for security vulnerabilities before pushing to production, do they?
评论 #6315790 未加载
评论 #6315846 未加载
评论 #6315773 未加载
meatsockover 11 years ago
wow that&#x27;s a nice bounty for changing two parameters on the end of a URL.
评论 #6315908 未加载
nivlaover 11 years ago
As I understand it, the exploit involves crafting a URL to send in a removal request to the Facebook support. Wouldn&#x27;t this count as social engineering or were the removal requests automated?<p>Regardless, well done!
评论 #6315919 未加载
评论 #6315861 未加载
tomphooleryover 11 years ago
Pretty sure Mark Zuckerberg has had his Facebook profile fucked with more than anyone else, judging by all these disclosures I&#x27;ve been reading :)