Tuesday, January 8, 2013
Facebook password reset vulnerability found by a security researcher
Facebook have a recovery page for compromised accounts "https://www.facebook.com/hacked". when clicked, it redirected to another page
"https://www.facebook.com/checkpoint/checkpointme?f=[userid]&r=web_hacked"
the parameter f equals to the user id, if any user id is given, password can be changed without any proper authentication.
The vulnerability was very simple to execute. This vulnerability has been confirmed and patched by Facebook Security Team.
Categories : facebook bug bounty , facebook hacking , facebook password reset vulnerability , fb account hacking , Sow Ching Shiong , Vulnerability , Zero Day Vulnerability
About Author:
Nauman Ashraf is a security researcher, developer and blogger. He is Founder and Chief Editor of The Hackers Post. Follow him on
Twitter
0 Responses to “ Facebook password reset vulnerability found by a security researcher ”
Post a Comment