Saturday, January 11, 2025
Home Technology Researcher nets fundamental reward for finding Fb bug ready to unlock the...

Researcher nets fundamental reward for finding Fb bug ready to unlock the gates to its inner systems


  • A safety flaw fresh in Fb’s ad platform has been fastened by Meta
  • The researcher who discovered the flaw used to be awarded a $100,000 bug bounty
  • The flaw allowed the researcher to successfully take address watch over of a Fb server

Meta has awarded cybersecurity researcher Ben Sadeghipour a bug bounty of $100,000 after he discovered a security vulnerability on Fb’s ad platform in October 2024.

The flaw allowed Sadeghipour to shuffle commands on the inner Fb server which housed the platform, giving him address watch over of the server.

In accordance with Sadeghipour, the unpatched bug allowed him to hijack the server using a headless Chrome browser, which is a version of the browser users shuffle from the computer’s terminal, to work alongside with Fb’s inner servers straight.

Share of wider researcher

The flaw in the platform used to be connected to a server that Fb extinct to gain and produce adverts, which used to be prone to a previously fastened flaw fresh in the Chrome browser, which Fb uses in its ad machine.

Sadeghipour told TechCrunch online promoting platforms are elegant targets due to the “there’s so well-known that occurs in the background of making these ‘adverts’ — whether or now no longer they are video, textual state material, or photos.”

“However on the core of it all it’s a bunch of data being processed on the server-aspect and it opens up the door for a ton of vulnerabilities,” Sadeghipour acknowledged.

The researcher confirms he didn’t take a look at out everything he would possibly presumably perchance be pleased once he used to be at some level of the server, though “what makes this unhealthy is that this used to be per chance a fragment of an inner infrastructure.”

Impress up to the TechRadar Educated newsletter to gain your entire prime news, thought, functions and steering your corporation desires to succeed!

After reporting the vulnerability to Meta, the bug took correct an hour to repair, Sadeghipour acknowledged, noting his discovery used to be fragment of ‘ongoing study on a particular utility with a particular motive’. This flaw in particular took him a few hours to identify, however Meta worked with him to fleet patch the bug and offered a bounty that used to be ‘method past’ expectations, he confirmed in a LinkedIn put up.

Worm bounties were on the upward thrust recently, with Google severely rising its rewards for researchers who take half in the program, so safety study is getting extra profitable.

You would possibly presumably perchance also additionally like

RELATED ARTICLES

Researcher nets fundamental reward for finding Fb bug ready to unlock the gates to its inner systems

A security flaw found in Facebook's ad platform has been fixed by Meta The researcher who discovered the flaw was awarded a $100,000 bug bounty The flaw allowed the researcher to effectively take control of a Facebook server Meta has awarded cybersecurity researcher Ben Sadeghipour a bug bounty of $100,000 after he discovered a security

DJI’s Mic Mini might perchance correct receive met its match: the diminutive, stamp-free Hollyland Lark M2S wireless mic

(Image credit: Hollyland) Hollyland announces new Lark M2S wireless mic to rival DJI and Rode The M2S is available in twin mic / receiver kits for around $139 / £130 It features a discreet logo-free design and weighs just 7g There's no shortage of wireless mics for content creators in 2025, with the likes of

I saw wireless earbuds which might maybe well be also air purifiers, and so that they claim to be a maskless cloak

(Image credit: Future) Like many world-changing events, new applications of existing technology can lead to some interesting concepts. For example, the Covid-19 pandemic led to the creation of masks featuring audio components. The controversial Razer Zephyr had external speakers, will.i.am’s Xupermask Honeywell collaboration had earbuds, and there was Dyson's air purifier mask headphones combo, of

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular

Researcher nets fundamental reward for finding Fb bug ready to unlock the gates to its inner systems

A security flaw found in Facebook's ad platform has been fixed by Meta The researcher who discovered the flaw was awarded a $100,000 bug bounty The flaw allowed the researcher to effectively take control of a Facebook server Meta has awarded cybersecurity researcher Ben Sadeghipour a bug bounty of $100,000 after he discovered a security

DJI’s Mic Mini might perchance correct receive met its match: the diminutive, stamp-free Hollyland Lark M2S wireless mic

(Image credit: Hollyland) Hollyland announces new Lark M2S wireless mic to rival DJI and Rode The M2S is available in twin mic / receiver kits for around $139 / £130 It features a discreet logo-free design and weighs just 7g There's no shortage of wireless mics for content creators in 2025, with the likes of

I saw wireless earbuds which might maybe well be also air purifiers, and so that they claim to be a maskless cloak

(Image credit: Future) Like many world-changing events, new applications of existing technology can lead to some interesting concepts. For example, the Covid-19 pandemic led to the creation of masks featuring audio components. The controversial Razer Zephyr had external speakers, will.i.am’s Xupermask Honeywell collaboration had earbuds, and there was Dyson's air purifier mask headphones combo, of

Bangladesh Opener Tamim Iqbal Proclaims Retirement From Global Cricket

Bangladesh opener Tamim Iqbal on Friday announced his retirement from international cricket. Notably, this is the second time Tamim has called time on his career, having previously retired in July 2023, only to reverse the decision within 24 hours after intervention from Bangladesh's then-prime minister Sheikh Hasina. According to a Cricbuzz report, the 35-year-old Tamim

Recent Comments