Blog | G5 Cyber Security

Facebook bug bounty program pays highest reward to date

Brazilian Security Engineer Reginaldo Silva was awarded a $33,500 bounty for disclosing an XML external entities vulnerability in a PHP page. Facebook confirmed the vulnerability as a potential RCE bug in a statement in their blog yesterday. The bug was discovered back in November and began the disclosure process with Facebook shortly after. However, Silva wanted to wait on disclosing it to Facebook until he had a full Remote Code Execution (RCE) bug produced, but when he returned after a quick-lunch break, the bug was already patched.”]

Source: https://blog.malwarebytes.com/cybercrime/2014/01/facebook-bug-bounty-program-pays-highest-reward-to-date/

Exit mobile version