Big Bounties For Invisible Post And Account Takeover Vulnerabilities Awards For Facebook Cybers Guards
In November, bug bounty hunter Pouya Darabi discovered that an intruder could generate invisible posts on any Facebook page, including authenticated pages, without any permission on the targeted page. When reviewing Innovative Hub, a service that allows Facebook users to build and preview advertisements for Facebook, Instagram or Messenger, the investigator found the flaw. Creative Hub helps users to work on ad mockups and, by making an invisible post on the chosen website, the advertisements can be previewed....