📜 ⬆️ ⬇️

Vulnerability in Facebook has opened access to private photo users (including Zuckerberg)



Of course, not only Zuckerberg's photos could be accessed by those who discovered a new vulnerability on the social networking site Facebook. But, as always, it was precisely the access to the private photos of the head of this social network that helped the Facebook tech support to move faster and close the detected vulnerability. As for the latter, everything is quite simple there, and perhaps this vulnerability is not so new, they just did not talk about it at every corner. Whatever it was, it’s all a matter of a recent function that allows you to send multiple complaints at the same time to “inappropriate photos” or illegal content on someone’s page.

This may be the notorious child porn, just nudity or something else like that. A feature recently introduced on Facebook allowed you to send a complaint to several photos at the same time, with the option “take action by selection”. Enabling this option showed recent photos from the profile of a user that could be rated as “inappropriate”. The function is, in general, harmless, but the developers missed one bug that opens access to the private photos of any user when using this very new option.
')
Of course, those who discovered the vulnerability, immediately began to check the opportunities opened on the profile of Zuckerberg. And the testers did it all, and the resulting private photos of the creator of Facebook were uploaded to imgur.com . There is nothing special in the photographs, but of course, the hype around this business still rose serious. Probably, the photos will soon be deleted from imgur, but for now they are still hanging there.

And yes, the vulnerability, due to which it was possible to view the private photos of any users, is already closed. Here, really, the best way to draw the attention of developers to any problems with a resource is to apply a vulnerability to any of the managers or owners of this resource.

Via mashable

Source: https://habr.com/ru/post/134157/


All Articles