TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Delete any Photo from Facebook by Exploiting Support Dashboard

114 点作者 costapopescu超过 11 年前

8 条评论

kristofferR超过 11 年前
This guy was lucky to be proficient enough in English to recieve the bounty, unlike this guy: <a href="http://www.theverge.com/2013/8/18/4633046/facebook-security-bug-let-anyone-post-on-walls" rel="nofollow">http:&#x2F;&#x2F;www.theverge.com&#x2F;2013&#x2F;8&#x2F;18&#x2F;4633046&#x2F;facebook-security-...</a>
评论 #6316077 未加载
评论 #6315760 未加载
评论 #6317183 未加载
lifeformed超过 11 年前
Facebook should make a &quot;Hack Me&quot; profile for people to mess with, so they don&#x27;t have to use Zuckerberg&#x27;s instead.
评论 #6315884 未加载
singold超过 11 年前
Maybe now we can delete our own facebook photos...
pearjuice超过 11 年前
Is it still worth it to follow every link on Facebook and check the URLs&#x2F;AJAX requests whether the parameters can be tampered with? At Facebook&#x27;s scale I always assumed there would be someone full-time employed to do this. In fact, I wouldn&#x27;t mind if it was good paying. Just give me all the Facebook frontend endpoints and I will go by them one-by-one. Manually. I will even document the test cases and what could be intercepted, changed or can be improved in terms of validation.
评论 #6317412 未加载
loceng超过 11 年前
Facebook really doesn&#x27;t test anything for security vulnerabilities before pushing to production, do they?
评论 #6315790 未加载
评论 #6315846 未加载
评论 #6315773 未加载
meatsock超过 11 年前
wow that&#x27;s a nice bounty for changing two parameters on the end of a URL.
评论 #6315908 未加载
nivla超过 11 年前
As I understand it, the exploit involves crafting a URL to send in a removal request to the Facebook support. Wouldn&#x27;t this count as social engineering or were the removal requests automated?<p>Regardless, well done!
评论 #6315919 未加载
评论 #6315861 未加载
tomphoolery超过 11 年前
Pretty sure Mark Zuckerberg has had his Facebook profile fucked with more than anyone else, judging by all these disclosures I&#x27;ve been reading :)