It's well known that if your Facebook account only gives access to your friends, only they can post on your wall. Khalil Shreateh, an IT expert from Palestine, claims to have discovered a vulnerability that allows anyone to post a link to other people's Facebook accounts, even if they don't give access. Shreateh reported the bug to Facebook recently, but the company ignored him and decided it wasn't a vulnerability.
Shreateh tested the vulnerability on the wall of Sarah Goodin – a friend of Mark Zuckerberg – before reporting it through Facebook’s whitehat reporting service. The service rewards researchers who find bugs in Facebook’s code with at least $500 per bug. Shreateh sent a message to Facebook explaining the details of the vulnerability and noting that the security team might not be able to see his post on Goodin’s wall since it only allows her friends to see it. Attaching a screenshot, a Facebooknamed Emrakul responded by saying: “Sorry this is not a bug” without asking for additional information.
Undeterred by the response, Shreateh decided to post the bug on Mark Zuckerberg. A few minutes later, a Facebook, Ola Okelola, contacted Shreateh asking for more details about the exploit. Facebook disabled his account, apparently fearing a wider security breach. Shreateh’s account has now been reactivated, but the company continues to claim that they “do not have enough technical information” to take action. In an email sent to Shreateh, a Facebook security engineer – who goes by the name Joshua – claims that the company “is unable to pay you for this vulnerability because your actions violated our Terms of Service.”
While the details of the exploit don't appear to have been made public, no one knows what Shreateh's next move will be. TheVerge , which first reported the story, reached out to Facebook to verify the details of the bug. The social network has yet to respond.

