Delete any Photo from Facebook by Exploiting Support Dashboard


Indian Security Enthusiast ‘Arul Kumar‘ recently reported an interesting Facebook vulnerability that allowed him to delete any Facebook image within a minute.

Facebook Bug Bounty program rewarded him with  $12,500 USD for helping the Facebook Security team to patch this critical loophole in their own “Support Dashboard“.
The flaw is critical because using this exploitation method hacker can also delete Mark Zuckerberg’s (Facebook Founder) Photos from his Photo Album, or even from wall of any verified page too.
Arul posted on his blog, “The Support Dashboard is a portal designed to help you track the progress of the reports you make to Facebook. From your Support Dashboard, you can see if your report has been reviewed by Facebook employees who assess reports 24 hours a day, seven days a week.”
That means, if you will report abuse the targeted image and send a Photo Removal Request, Facebook Server Will automatically generates Photo removal Link and send to the Owner. If the Owner of that image clicks that link, Photo will be removed.
Hacker explained that two parameters i.e. Photo_id & Owners Profile_id are vulnerable and if hacker will change modifies the values of these parameters using Inspect Element feature of Google Chrome, then the hacker is able to receive that photo removal link to his own Inbox of another account, rather than sending to the owner’s Inbox.
Video demonstration:
This way trick involves just two attackers Facebook account, no victim’s interaction and hackers were able to delete any Shared-Tagged photos, Photo from Status & Photo album, Pages, Groups and also from Comments.
Advertisements

Leave a Reply

Please log in using one of these methods to post your comment:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s