Get a Pentest and security assessment of your IT network.

News

Researcher rewarded $33k for snatching password file from Facebook’s server

Brazilian computer engineer Reginaldo Silva discovered a bug that would eventually lead him to rewards from Google and Facebook. The XXE bug, a XML External Entity Expansion (XXE) bug, was easily targeted on domains that offer OpenID authentication. Facebook’s server offered read access to most everything, including the /etc/passwd file. The social networking giant offered Silva $33,500 USD in compensation. To date, the sum represents the social network’s largest bug bounty payout. At present, Silva says that many implementations of OpenID are still vulnerable to the bug.”]

Source: https://www.csoonline.com/article/2136996/researcher-rewarded–33k-for-snatching-password-file-from-facebook-s-server.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Google Chrome will block code injection from third-party software within 14 months