Delete any Photo from Facebook by Exploiting Support Dashboard
arulxtronix.blogspot.in
Delete any Photo from Facebook by Exploiting Support Dashboard
1–10 of 32 posts
Re: Delete any Photo from Facebook by Exploiting Support Dashboard
#2Re: Delete any Photo from Facebook by Exploiting Support Dashboard
#3Re: Delete any Photo from Facebook by Exploiting Support Dashboard
#4This guy was lucky to be proficient enough in English to recieve the bounty, unlike this guy: http://www.theverge.com/2013/8/18/4633046/facebook-security-...
There, I did it. Haha.
Can we stop beating dead horses, we all read Hacker News around here?
Re: Delete any Photo from Facebook by Exploiting Support Dashboard
#5Facebook really doesn't test anything for security vulnerabilities before pushing to production, do they?
Re: Delete any Photo from Facebook by Exploiting Support Dashboard
#6Facebook really doesn't test anything for security vulnerabilities before pushing to production, do they?
For now, the best you can hope for is a layered defense and rigorous dev and ops practices to help minimize the attack surface and reduce the overall damage a single successful attack can achieve.
Re: Delete any Photo from Facebook by Exploiting Support Dashboard
#7Re: Delete any Photo from Facebook by Exploiting Support Dashboard
#8Facebook really doesn't test anything for security vulnerabilities before pushing to production, do they?
Testing can only ever go so far - bugs and vulnerabilities exist everywhere, even in Facebook.
Re: Delete any Photo from Facebook by Exploiting Support Dashboard
#9Regardless, well done!
Re: Delete any Photo from Facebook by Exploiting Support Dashboard
#10Facebook really doesn't test anything for security vulnerabilities before pushing to production, do they?
They most likely do test for security vulnerabilities. However, the attack surface and overall complexity is so large that things will slip by even with the most rigorous testing. For now, the best you can hope for is a layered defense and rigorous dev and ops practices to help minimize the attack surface and reduce the overall damage a single successful attack can achieve.
Automated testing/fuzzing could find this, but probably better training/practices would be easier to get right and save time/money in the long run.