Advertisement
khalil-sh

Untitled

Aug 15th, 2013
11,968
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.36 KB | None | 0 0
  1. Hi Ḱhalil,
  2.  
  3.  
  4.  
  5. I am sorry this is not a bug.
  6.  
  7. Thanks,
  8.  
  9. Emrakul
  10. Security
  11. Facebook
  12.  
  13. -----Original Message to Facebook-----
  14. From: kh*****@hotmail.com
  15. To:
  16. Subject: urgent : post to non friends facebook users wall .
  17.  
  18. Name: Ḱhalil
  19. E-Mail: kh*****@hotmail.com
  20. Type: privacy
  21. Scope: www
  22. Description: dear facebook team .
  23.  
  24. my name is khalil ***** , iam ** years old from palestine .
  25. i finished school with B.A degree in Infromation Systems .
  26.  
  27. i would like to report a bug in your main site (www.facebook.com) which i discovered .
  28.  
  29.  
  30. i'am reporting this bug for the second time and i know that you offer money to whitehat people .
  31.  
  32.  
  33. repro:
  34. the vulnerability allow's facebook use to share posts to non friends facebook users , i made a post to sarah.goodin timeline and i got success post
  35.  
  36. link - > https://www.facebook.com/10151857333098885
  37.  
  38. of course you may cant see the link because sarah's timeline friends posts shares only with her friends , you need to be a friend of her to see that post or you can use your own authority . i can see that post i made to sarah's wall cause i'am the one who post either whatever iam not on her friend list .
  39.  
  40. this is a picture shows that post :
  41.  
  42. https://fbcdn-sphotos-h-a.akamaihd.net/hphotos-ak-ash4/q71/s720x720/999429_10151857336258885_2061448780_n.jpg
  43.  
  44.  
  45.  
  46.  
  47.  
  48. -----End Original Message to Facebook-----
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement