HomeSecurityFacebook vulnerability allows photo albums to be deleted

Facebook vulnerability allows photo albums to be deleted

 

facebook

A serious vulnerability in Facebook, which was recently discovered, could allow anyone to delete an entire photo album from a Facebook profile, without having to authenticate.

Security researcher Laxman Muthiyah, in an interview with Hacker News, says that the vulnerability lies in the Graph API mechanism, which allows “a hacker to delete any photo album on the popular social networking site. Any photo album belonging to a group or a user or even a page could be very easily deleted.”

According to the Facebook developers' report, you can't delete albums using the Graph API, but the Indian security researcher found a way to delete not only his own, but also other photo albums on Facebook, in a matter of seconds.

In general, the Facebook Graph API requires an access token to read or write user data, which grants limited access to just one application. However, Laxman discovered that his own “access token” generated for the mobile version of Facebook could be exploited to remove all photo albums published by any Facebook user.

To delete a photo album from the victim's Facebook account, the attacker only needs to send a request based on the HTTP API Graph with the victim's photo album ID and the attacker's account access token generated for the site's Android app.

As part of the Facebook Bug Bounty, the researcher received $12,500 for finding and helping the site's team fix the problem.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS