How to delete any Facebook videos

Pranav Hivarekar, is a security researcher from India. The researcher discovered a on the Facebook platform, which allowed him to delete any video he wanted.

The was in a new Facebook feature added to the service earlier this month, when the social network allowed videos and comments to be posted on other posts. hack Facebook

The researcher reports that with some with some API requests to Facebook, he was able to delete any video uploaded to the platform, based on its ID.

"Αυτό το σφάλμα είναι η απόδειξη ότι η λογική δεν είναι σωστή και δεν είναι κάποια τεχνικά ατέλεια που βλέπουμε όπως RCE, SSRF κλπ," εξηγεί ο ερευνητής.

The subject, according to Hivarekar, is created when a user uploads a video as a comment. The video goes up in its profile on Facebook, and this gives it a specific ID. Then after posting to the desired location, there is this ID.

In his tests, the researcher discovered that he could generate comments through Facebook's API, he could then send another API request to attach any video ID from any user in his comment. Of course after all this using another API request could delete the comment.

Hivarekar mentioned that Facebook developers forgot to add s to prevent videos from being deleted by people who didn't upload the videos.

The researcher reported the vulnerability to Facebook through the bug bounty program on June 11, days after the social network launched the new feature.

On the other hand Facebook provided a temporary solution after 23 minutes, and then fixed the error completely 11 hours later. For the extremely critical bug reported by the Facebook researcher, the social network rewarded him with a five-digit reward.

More details

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).