Hacker claims to be able to delete photo albums from Facebook (Video)

Discussion in 'Forum for discussion of ANTICHAT' started by K800, 14 Feb 2015.

  1. K800

    K800 Nobody's Fool

    Joined:
    25 Dec 2010
    Messages:
    2,191
    Likes Received:
    3,828
    Reputations:
    372
    Security researcher Laxman Muthiyah has posted his hack of Facebook showing how he was able to accomplish both the deletion of his own photo album and then that of a "victim".


    Though Facebook claims this isn't possible, it is quite the opposite case and proof is posted for everyone to see.

    Essentially he utilized the Graph API. By generating the he should not be able to accomplish the feat, but by generating a token for the mobile version of the social network that changed things.

    "The album got deleted! So i got the key to delete all of your Facebook photos", Muthiya calmly states. Of course he won't do this, he's only proving a point. But that point should be acted upon quickly by the service because, now that it's out there, someone will certainly begin using it "just for fun".

    Fortunately, it has been fixed, so the need to worry about this is no longer a concern. Facebook also awarded Mr. Muthiyah $12,500 for finding the flaw.
     
    #1 K800, 14 Feb 2015
    Last edited: 28 Mar 2022