Blog | G5 Cyber Security

Facebook Hacker received $33,500 reward for Remote code execution vulnerability

Facebook has paid out its largest Bug Bounty ever of $33,500 to a Brazilian security researcher for discovering and reporting a critical Remote code execution vulnerability. Facebook allows users to access their accounts using OpenID in which it receives an XML document from 3rd service and parse it to verify that it is indeed the correct provider or not. In November 2013, while testing Facebook’s ‘Forgot your password’ functionality, he found that the OpenID process could be manipulated to execute any command on the Facebook server remotely and also allows to read arbitrary files on the webserver.

Source: https://thehackernews.com/2014/01/facebook-hacker-received-33500-reward.html

Exit mobile version