Facebook Fixes Flaw That Could've Let Anyone Access Your Account

Advertisement
By Manish Singh | Updated: 17 March 2016 19:09 IST

Facebook has awarded a sum of $15,000 (roughly Rs. 10 lakhs) to an India-born security researcher. Anand Prakash received the bug bounty from Facebook after disclosing a vulnerability in the social juggernaut's website that enabled an attacker to gain access to anyone's account.

Prakash discovered a vulnerability on Facebook website that allowed him to change the user account password for any account. He reported the vulnerability to Facebook last month and the company has since patched it. Prakash has now shed light on the vulnerability, and also demonstrated it in works on a video.

The security hole resided in company's developer portal, beta.facebook.com, which is designed for developers to perform tests before rollout to the general public. Facebook sends users a 6-digit code over email or text message upon password reset request. To prevent abuse or potential ill intents, Facebook allows only a certain number of attempts. Turns out, over at the beta website, a user could make any number of guesses.

Advertisement

In a blog post, Prakash wrote that he utilised Burp Suite, a popular testing tool. Prakash noted that because it's only a six-digit number, and brute forcing password is possible, it was not impossible to crack into someone's account, guessing the reset password.

Advertisement

"[...] I looked out for the same issue on beta.facebook.com and mbasic.beta.facebook.com and interestingly rate limiting was missing on forgot password endpoints," he wrote in a blog post. "I tried to takeover my account ( as per Facebook's policy you should not do any harm on any other users account) and was successful in setting new password for my account. I could then use the same password to login in the account."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Xbox Cloud Gaming Launched in India: Here's How You Can Start Playing
  2. Google Pixel Phones to Get November 2025 Update Soon, Details Leak Online
  3. Oppo Reno 15 Lineup Could be Powered by This MediaTek Dimensity Chipset
  4. Google Play Store to Penalise Apps Causing Excessive Battery Drain
  5. Apple Watch Series 11 Review
  6. Lava Agni 4 Key Specifications Leak Ahead of India Launch Next Week
  7. Motorola Edge 70 Ultra Surfaces on Benchmarking Site Ahead of Launch
  1. Samsung Galaxy S26 Series Could Launch With Faster Wireless Charging Support; Display Sizes Leaked
  2. WhatsApp for Android May Let Users Reserve Same Usernames Used on Facebook and Instagram
  3. The Elder Scrolls 6 Is 'Still a Long Way Off', Says Bethesda Director Todd Howard
  4. Oppo Reno 14F 5G Star Wars Edition Launch Date Set For Mid-November
  5. Bitcoin Holds Above $105,000 as Institutional Demand and Regulatory Progress Lift Sentiment
  6. Motorola Edge 70 Ultra Allegedly Surfaces on Geekbench With Snapdragon 8 Gen 5 Chipset
  7. Microsoft Launches Xbox Cloud Gaming in India: Here's How You Can Start Cloud Streaming Games
  8. Google Meet Finally Adds Support for Full Emoji Library to Enhance In-Call Reactions
  9. Oppo Reno 15 Series Might Feature the Same MediaTek Dimensity Chip as its Predecessor
  10. Samsung Galaxy Smartphones Targeted By Spyware Landfall for Over a Year
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.