Saturday, January 11, 2025
Home Technology Researcher nets fundamental reward for finding Fb bug ready to unlock the...

Researcher nets fundamental reward for finding Fb bug ready to unlock the gates to its inner systems


  • A safety flaw fresh in Fb’s ad platform has been fastened by Meta
  • The researcher who discovered the flaw used to be awarded a $100,000 bug bounty
  • The flaw allowed the researcher to successfully take address watch over of a Fb server

Meta has awarded cybersecurity researcher Ben Sadeghipour a bug bounty of $100,000 after he discovered a security vulnerability on Fb’s ad platform in October 2024.

The flaw allowed Sadeghipour to shuffle commands on the inner Fb server which housed the platform, giving him address watch over of the server.

In accordance with Sadeghipour, the unpatched bug allowed him to hijack the server using a headless Chrome browser, which is a version of the browser users shuffle from the computer’s terminal, to work alongside with Fb’s inner servers straight.

Share of wider researcher

The flaw in the platform used to be connected to a server that Fb extinct to gain and produce adverts, which used to be prone to a previously fastened flaw fresh in the Chrome browser, which Fb uses in its ad machine.

Sadeghipour told TechCrunch online promoting platforms are elegant targets due to the “there’s so well-known that occurs in the background of making these ‘adverts’ — whether or now no longer they are video, textual state material, or photos.”

“However on the core of it all it’s a bunch of data being processed on the server-aspect and it opens up the door for a ton of vulnerabilities,” Sadeghipour acknowledged.

The researcher confirms he didn’t take a look at out everything he would possibly presumably perchance be pleased once he used to be at some level of the server, though “what makes this unhealthy is that this used to be per chance a fragment of an inner infrastructure.”

Impress up to the TechRadar Educated newsletter to gain your entire prime news, thought, functions and steering your corporation desires to succeed!

After reporting the vulnerability to Meta, the bug took correct an hour to repair, Sadeghipour acknowledged, noting his discovery used to be fragment of ‘ongoing study on a particular utility with a particular motive’. This flaw in particular took him a few hours to identify, however Meta worked with him to fleet patch the bug and offered a bounty that used to be ‘method past’ expectations, he confirmed in a LinkedIn put up.

Worm bounties were on the upward thrust recently, with Google severely rising its rewards for researchers who take half in the program, so safety study is getting extra profitable.

You would possibly presumably perchance also additionally like

RELATED ARTICLES

Alick Athanaze hits 98 on first day of WI heat-up match in Pakistan

Sports Roneil Walcott 19 Hrs Ago Alick Athanaze bats during day one for West Indies in a warm-up match against Pakistan Shaheens in Islamabad, Pakistan on January 10. - Photo courtesy Pakistan Cricket Board Media STYLISH left-handed batsman Alick Athanaze missed out on three figures on the opening day of West Indies' warm-up match against

Debe taxi driver robbed at gunpoint

News Rishard Khan 19 Hrs Ago - File photo POLICE are searching for a man who held up a Debe taxi driver at gunpoint on the afternoon of January 9. The 56-year-old victim told police he was working in his grey Nissan Wingroad along the San Fernando-Penal route when, on reaching the Penal taxi stand

Belmont man held in Siparia with ammunition

News Rishard Khan 19 Hrs Ago - File photo A Belmont man was arrested in Siparia on the evening of January 9 after police discovered illegal ammunition in his possession. Police said officers were on an anti-crime exercise in the Fyzabad district when they received information that took them to a home on Zachariah Avenue

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular

Alick Athanaze hits 98 on first day of WI heat-up match in Pakistan

Sports Roneil Walcott 19 Hrs Ago Alick Athanaze bats during day one for West Indies in a warm-up match against Pakistan Shaheens in Islamabad, Pakistan on January 10. - Photo courtesy Pakistan Cricket Board Media STYLISH left-handed batsman Alick Athanaze missed out on three figures on the opening day of West Indies' warm-up match against

Debe taxi driver robbed at gunpoint

News Rishard Khan 19 Hrs Ago - File photo POLICE are searching for a man who held up a Debe taxi driver at gunpoint on the afternoon of January 9. The 56-year-old victim told police he was working in his grey Nissan Wingroad along the San Fernando-Penal route when, on reaching the Penal taxi stand

Belmont man held in Siparia with ammunition

News Rishard Khan 19 Hrs Ago - File photo A Belmont man was arrested in Siparia on the evening of January 9 after police discovered illegal ammunition in his possession. Police said officers were on an anti-crime exercise in the Fyzabad district when they received information that took them to a home on Zachariah Avenue

Researcher nets fundamental reward for finding Fb bug ready to unlock the gates to its inner systems

A security flaw found in Facebook's ad platform has been fixed by Meta The researcher who discovered the flaw was awarded a $100,000 bug bounty The flaw allowed the researcher to effectively take control of a Facebook server Meta has awarded cybersecurity researcher Ben Sadeghipour a bug bounty of $100,000 after he discovered a security

Recent Comments