Friday, March 29, 2024

Discovered Critical Bug allowed to Delete any Videos from Facebook

Security researcher Dan Melamed came across the vulnerability in June 2016. The bug is some ways similar to a vulnerability discovered by another researcher around the same time. There’s just one major exception.

Dan Melamed said ,c  Dan Melamed In addition,  also had the ability to disable commenting on any video. This allows a bad actor the ability to delete videos on Facebook without permission or authentication.

The security researcher exploited the flaw by first creating a public event. On the Discussion part of the event, he uploaded a video and intercepted the POST request using Fiddler.

This request, which looks something like https://www.facebook.com/media/upload/photos/composer/?av<Profile ID>&dpr=1, comes with composer_unpublished_photo[0]=<Video ID>; as one of its parameters.

The crux of the vulnerability rested with the Video ID value. All someone needed to do was change the Video ID to any other video on the social media platform. Sure, Facebook would then have responded with a server error, but the new video would have displayed just fine.

From there, an attacker could have simply deleted the video. Doing so would have removed the video from the social networking site.

Computer criminals might have any number of reasons for deleting a video off Facebook. Perhaps they work for a company and want to sabotage a marketing campaign of one of their employer’s competitors.

Alternatively, they might just be jerks and so don’t care if the world doesn’t see your toddler taking their first few steps.

Fortunately, we don’t worry to have worry about this vulnerability any longer. Facebook, patched the vulnerability a short time after Melamed reported the flaw to its security teams. A $10,000 bug bounty award shortly followed after that.

Website

Latest articles

IT and security Leaders Feel Ill-Equipped to Handle Emerging Threats: New Survey

A comprehensive survey conducted by Keeper Security, in partnership with TrendCandy Research, has shed...

How to Analyse .NET Malware? – Reverse Engineering Snake Keylogger

Utilizing sandbox analysis for behavioral, network, and process examination provides a foundation for reverse...

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus Labs, the leading Web3 security infrastructure provider, has unveiled a groundbreaking report highlighting...

Wireshark 4.2.4 Released: What’s New!

Wireshark stands as the undisputed leader, offering unparalleled tools for troubleshooting, analysis, development, and...

Zoom Unveils AI-Powered All-In-One AI Work Workplace

Zoom has taken a monumental leap forward by introducing Zoom Workplace, an all-encompassing AI-powered...

iPhone Users Beware! Darcula Phishing Service Attacking Via iMessage

Phishing allows hackers to exploit human vulnerabilities and trick users into revealing sensitive information...
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Mitigating Vulnerability Types & 0-day Threats

Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

Related Articles