Thursday, April 17, 2025
HomeCVE/vulnerabilityDiscovered Critical Bug allowed to Delete any Videos from Facebook

Discovered Critical Bug allowed to Delete any Videos from Facebook

Published on

SIEM as a Service

Follow Us on Google News

Security researcher Dan Melamed came across the vulnerability in June 2016. The bug is some ways similar to a vulnerability discovered by another researcher around the same time. There’s just one major exception.

Dan Melamed said ,c  Dan Melamed In addition,  also had the ability to disable commenting on any video. This allows a bad actor the ability to delete videos on Facebook without permission or authentication.

The security researcher exploited the flaw by first creating a public event. On the Discussion part of the event, he uploaded a video and intercepted the POST request using Fiddler.

- Advertisement - Google News

This request, which looks something like https://www.facebook.com/media/upload/photos/composer/?av<Profile ID>&dpr=1, comes with composer_unpublished_photo[0]=<Video ID>; as one of its parameters.

The crux of the vulnerability rested with the Video ID value. All someone needed to do was change the Video ID to any other video on the social media platform. Sure, Facebook would then have responded with a server error, but the new video would have displayed just fine.

From there, an attacker could have simply deleted the video. Doing so would have removed the video from the social networking site.

Computer criminals might have any number of reasons for deleting a video off Facebook. Perhaps they work for a company and want to sabotage a marketing campaign of one of their employer’s competitors.

Alternatively, they might just be jerks and so don’t care if the world doesn’t see your toddler taking their first few steps.

Fortunately, we don’t worry to have worry about this vulnerability any longer. Facebook, patched the vulnerability a short time after Melamed reported the flaw to its security teams. A $10,000 bug bounty award shortly followed after that.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Microsoft Vulnerabilities Reach Record High with Over 1,300 Reported in 2024

The 12th Edition of the Microsoft Vulnerabilities Report has revealed a significant surge in...

43% of Top 100 Enterprise Mobile Apps Expose Sensitive Data to Hackers

A comprehensive study by zLabs, the research team at Zimperium, has found that over...

LummaStealer Exploits Windows Utility to Run Remote Code Disguised as .mp4 File

The Cybereason Global Security Operations Center (GSOC) has shed light on the sophisticated tactics...

Managing Burnout in the SOC – What CISOs Can Do

The Security Operations Center (SOC) is the nerve center of modern cybersecurity, responsible for...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Critical Erlang/OTP SSH Vulnerability Allow Hackers Execute Arbitrary Code Remotely

A major security flaw has been uncovered in the widely used Erlang/OTP SSH implementation,...

CISA Warns of Potential Credential Exploits Linked to Oracle Cloud Hack

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a public warning following reports...

Critical Flaw in PHP’s extract() Function Enables Arbitrary Code Execution

A critical vulnerability in PHP’s extract() function has been uncovered, enabling attackers to execute arbitrary code...