Researcher demos Facebook bug with Zuckerberg Wall post

By

'Dear Mark, sorry for breaking your privacy'.

A security researcher said he was forced to publish an unauthorised post on Mark Zuckerberg's Facebook Wall to demonstrate a privacy vulnerability to the social networking giant.

Researcher demos Facebook bug with Zuckerberg Wall post

Khalil Shreateh described in a blog how he reportedly disclosed the unconfirmed bug to Facebook by posting an update to the Wall owned by a friend of Zuckerberg who he was not connected to, a feat which breached site privacy policies. 

 

According to a purported email chain, Shreateh offered to post an update to an account held by the Facebook security team as a proof of concept, but was told only that the alleged vulnerability was not a bug.

He then posted an update to Zuckerberg's Wall where a Facebook software engineer reached out requesting more details.

From there, Shreateh's account was temporarily suspended and he was told he would not receive the cash bug bounty rewards on offer from the site since he did not report the flaw according to normal procedures.

 

Facebook did not immediately return requests for comment.

Cipherlaw attorney James Denaro said on Twitter he would advise against Facebook paying out a bug bounty because the site could find itself in a "legally risky" scenario.

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

Australia's super funds told to assess authentication controls

Australia's super funds told to assess authentication controls

Woolworths' CSO is Optus-bound

Woolworths' CSO is Optus-bound

CBA looks to GenAI to assist 1200 'security champions'

CBA looks to GenAI to assist 1200 'security champions'

Hackers abuse modified Salesforce app to steal data, extort companies

Hackers abuse modified Salesforce app to steal data, extort companies

Log In

  |  Forgot your password?