
Facebook Bug Lets Hackers Delete Any Video
A security researcher has discovered a critical bug in Facebook that could allow a would-be hacker to delete any video posted on the social networking site by any user. The critical bug was discovered by Dan Melamed in June 2016, when he discovered that he could remotely delete any video on Facebook without needing the user's permission or Facebook ID. He discovered that he could also disable commenting on the video using the same bug.
How this error works:
The flaw discovered by Melamed is similar to another bug disclosed by security researcher Pranav Hivarekar. Hivarekar had discovered a way to link the victim's video to a comment so that it could be deleted.
To exploit this vulnerability, Melamed created the first public event on his Facebook and uploaded a video to the event’s Discussion. While uploading the video, Melamed forged the POST request and replaced the ID on his video with the ID of any other video on the social media platform. In this case, we are talking about the victim’s video that he wanted to delete. Facebook responded to Melamed’s request with a server error, i.e. “This content is no longer available,” but the new video was successfully posted.
Melamed then discovered that when he deleted his event, the entire video posted by the unknown victim was also deleted.
He also claims to have discovered a way to disable commenting on any video, saying there is a drop-down section where you can find the option to “Turn off commenting,” which allows you to disable comments on the video of your choice. Melamed documented how the bug works and published it on his blog. Facebook recognized the bug he discovered as critical and rewarded him with $10,000 for reporting it. Facebook has also patched the bug so that it cannot be exploited further.
