Skip to main content

Swapping out video IDs lets programmer delete any Facebook video

Facebook Vulnerability - Deleting Any Video on Facebook
Uploading a video to an event page and swapping out the ID code could have allowed computer savvy hackers to overwrite any Facebook video, no matter who uploaded it. Dan Melamed, a security researcher, uncovered the vulnerability — and earned a cool $10,000 for showing Facebook the error.

Melamed found the vulnerability last June, but only shared the glitch Monday after a Facebook update had already corrected the issue. By attaching any Facebook video to an event post by grabbing some of the code and pasting it in while uploading another video, that stolen video pops up on the event page.

Recommended Videos

But what’s even more unnerving is that when that stolen video post is deleted, the original is also deleted from the owner’s page. Disabling the comments on that post through the event page could also disable comments on the original video.

Please enable Javascript to view this content

Melamed reported the vulnerability to Facebook at the end of June — a day later, the social media platform asked him to delete one of Facebook’s own videos to prove the glitch, and the next day, that’s what he did. Two weeks later, Facebook awarded him $10,000 for responsibly reporting the error.

Melamed is a self-described security researcher and web programmer — he hacks into programs to find weaknesses, then reports them to the company to fix before a hacker exploits the glitch. While the security issue was uncovered months ago, Melamed only shared how he was able to delete any Facebook video after Facebook removed the vulnerability — so hackers couldn’t use his findings as a how-to guide. He did not say when Facebook corrected the issue.

The video fix comes after a different security researcher discovered how to delete any Facebook album using only four lines of code — Facebook fixed that glitch within two hours. Facebook uses a Bug Bounty program to encourage hackers to report rather than exploit any uncovered weaknesses. Now five years old, Facebook has paid over five million dollars in “bounties” through the program.

Hillary K. Grigonis
Hillary never planned on becoming a photographer—and then she was handed a camera at her first writing job and she's been…
How to get verified on Instagram Threads
A verified account on Instagram Threads.

Like Twitter and Instagram, Instagram Threads allows users to become verified to confirm their identities and access some exclusive features. Similar to Twitter's verification process, you'll need to pay a monthly fee to be verified on Threads, so keep that price in mind as you get your verified Threads account set up.

So, without further ado, here's how to get verified on Instagram Threads in a few straightforward steps.

Read more
How to remove location data from your iPhone photos
How to transfer photos from an iPhone to an iPhone

We all love making memories, and a great way to collect those memories is to take a quick snap of a gorgeous landscape, a party in full swing, or a particularly incredible meal. The Apple iPhone now also adds a location to your pictures, meaning it can collate those images together into a location-themed album, or show you all the shots you've taken in a specific location. It's a fun little addition, and it's one that adds a lot of personality to the Photos app.

Read more
‘Photoshopped’ royal photo causes a stir
The Princess of Wales with her children.

[UPDATE: In a message posted on social media on Monday morning, Princess Kate said that she herself edited the image, and apologized for the fuss that the picture had caused. “Like many amateur photographers, I do occasionally experiment with editing," she wrote, adding, "I wanted to express my apologies for any confusion the family photograph we shared yesterday caused."]

Major press agencies have pulled a photo of the U.K.’s Princess of Wales and her children amid concerns that it has been digitally manipulated.

Read more