Skip to main content

Facebook pays researcher $12.5K bounty for uncovering image-deletion security flaw

money-facebook
Image used with permission by copyright holder

Arul Kumar isn’t the first person to be paid for spotting a security flaw in a widely used online service, and he certainly won’t be the last.

The 21-year-old electronics and communication engineer revealed this week that Facebook paid him $12,500 for spotting a software vulnerability that could allow a hacker to delete any image stored on the social networking site. While the company is known to pay out for discoveries like this, such a large amount is thought to be rare, meaning Facebook’s security team considered it to be potentially very damaging.

Ethical hacker

Kumar, who on his blog describes himself as someone “with a passion in ethical hacking”, discovered that the bug existed with all versions of all browsers for both PC and mobile. The engineer explained on his blog that he found the flaw by going through Facebook’s Support Dashboard, which is used for sending photo removal requests to company staff.

Such requests can also be sent direct to the person who uploaded the image via the photo removal request form. The uploader receives a link, which, if clicked, removes the image.

However, Kumar found a way for a hacker to generate a photo removal link and have it sent to their own inbox, thereby allowing them to delete the image without the uploader knowing.

After bringing the bug to the attention of Facebook via its Bug Bounty program, the company’s security team agreed to pay out $12,500 for his effort.

facebook flaw
Image used with permission by copyright holder

The program didn’t quite work in the intended way for Palestinian IT researcher Khalil Shreateh, however, when his initial bug report was essentially ignored by Facebook’s security team. Frustrated, Shreateh hacked CEO Mark Zuckerberg’s wall to demonstrate the flaw. Not surprisingly, the security team then took a greater interest in the bug, though said they couldn’t pay Shreateh as he’d violated the site’s terms of service by exploiting the vulnerability. Fortunately for the IT researcher, however, the story has a happy ending.

Bugs for cash

Payouts to independent researchers for bug discoveries has been going on for a while. According to PC World, Web giant Google has paid out around $580,000 over the last three years to independent security researchers who’ve pointed out security vulnerabilities among its online tools, while Mozilla has handed over a similarly large sum, $570,000. However, their respective methods of payment differ – whereas Mozilla pays a flat sum of $3,000 to those who spot a flaw, Google pays an amount anywhere between $500 and $10,000 depending on how serious it considers the bug to be.

Google also organizes the Pwnium browser penetration contest where participants can win up to $150,000 for spotting major Chrome bugs, while the annual Pwn2Own contest also offers payments to hackers who uncover security weaknesses in popular software and mobile devices.

[via Cnet]

Editors' Recommendations

Topics
Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Bluesky barrels toward 1 million new sign-ups in a day
Bluesky social media app logo.

Social media app Bluesky has picked nearly a million new users just a day after exiting its invitation-only beta and opening to everyone.

In a post on its main rival -- X (formerly Twitter) -- Bluesky shared a chart showing a sudden boost in usage on the app, which can now be downloaded for free for iPhone and Android devices.

Read more
How to make a GIF from a YouTube video
woman sitting and using laptop

Sometimes, whether you're chatting with friends or posting on social media, words just aren't enough -- you need a GIF to fully convey your feelings. If there's a moment from a YouTube video that you want to snip into a GIF, the good news is that you don't need complex software to so it. There are now a bunch of ways to make a GIF from a YouTube video right in your browser.

If you want to use desktop software like Photoshop to make a GIF, then you'll need to download the YouTube video first before you can start making a GIF. However, if you don't want to go through that bother then there are several ways you can make a GIF right in your browser, without the need to download anything. That's ideal if you're working with a low-specced laptop or on a phone, as all the processing to make the GIF is done in the cloud rather than on your machine. With these options you can make quick and fun GIFs from YouTube videos in just a few minutes.
Use GIFs.com for great customization
Step 1: Find the YouTube video that you want to turn into a GIF (perhaps a NASA archive?) and copy its URL.

Read more
I paid Meta to ‘verify’ me — here’s what actually happened
An Instagram profile on an iPhone.

In the fall of 2023 I decided to do a little experiment in the height of the “blue check” hysteria. Twitter had shifted from verifying accounts based (more or less) on merit or importance and instead would let users pay for a blue checkmark. That obviously went (and still goes) badly. Meanwhile, Meta opened its own verification service earlier in the year, called Meta Verified.

Mostly aimed at “creators,” Meta Verified costs $15 a month and helps you “establish your account authenticity and help[s] your community know it’s the real us with a verified badge." It also gives you “proactive account protection” to help fight impersonation by (in part) requiring you to use two-factor authentication. You’ll also get direct account support “from a real person,” and exclusive features like stickers and stars.

Read more