Facebook may have the largest photo database. Every day about 350 million photos are uploaded worldwide.
Security researcher Laxman Muthiyah discovered a way that he could, if he wished, delete every photo uploaded to the popular social network.
Luckily for Facebook and its 1.3 billion users, researcher Laxman Muthiyah had no malicious intent. He reported the bug to Facebook, and won $12,500.
The response from Facebook was immediate – credit to them, and the bug was fixed across the network within 2 hours.
Laxman says:
OMG 😀 the album got deleted! So i got the key to delete all of your Facebook photos 😛 lol 😀
Immediately reported this bug to Facebook security team. They were too fast in identifying this issue and there was a fix in place in less than 2 hours from the acknowledgment of the report.
Of course Laxman had other options.
The bug he discovered is a weapon. It could not kill anyone, but it could make hundreds of millions of people unhappy.
Laxman could probably sell the bug on the underground market and earn much more money than he got from Facebοok.
Or he could keep his discovery secret and exploit it himself for his own benefit, see LizardSquad. Do you think if LizardSquad had discovered the vulnerability they would have reported it to Facebοok?
Laxman discovered the bug while examining the Graph API of Facebook (Application Program Interface).
The Graph API helps connect Facebook with websites, applications, and other programs that need to integrate with Facebook.
It is a lightweight interface code that is driven by HTTP requests. It allows applications to do the same things that Facebook users do, but also many more.
Naturally, API users should not be able to edit or delete things that belong to someone else.
What Laxman discovered was a bug that allowed him to do exactly that, using an access token from the Facebook app for Android to authenticate himself.
The Facebook vulnerability was nothing more than four lines of code:
DELETE /
Host : graph.facebook.com
Content-Length: 245
access_token=
The identifiers of the Facebοok albums are numeric, which means that someone can start from 1 and simply continue until there is nothing left. Or for even faster, the hacker could create a script with the above code in a loop, starting from 1 up to one trillion.
Guess the result.
See the PoC
