Posted by : Unknown Friday, 3 January 2014

A Developer discovers a bug to re-enable poll questions and Facebook says: NOT A BUG!

Yesterday, An Egyptian Programmer and Information Security Analyst Mohamed AbdelBaset sent a report to Facebook security team telling them that he successfully bypassed the "Posting Check System" and re-enable the "Poll Questions" option again for the Fan pages which the Facebook administration had disabled it. Also, he could make it works on any personal profiles which wasn't enabled at any time before. he explained in his report that any big fan page or a public celebrity facebook account that has huge number of fans and interactions can make that to collect data and statistics and sell them to the interested companies which he think it was the main reason that facebook has to disable this feature.

But, As usual the Facebook Security team didn't admit it as a BUG. After a while he recieved this email:


"Hi Symbian,
The ability to post questions does not constitute a security or privacy issue: there is no risk to user data or privacy here.
Thanks,
Godot
Security
Facebook"

He explained more than once that this report is not a "Security Issue", but it compatible with two of "Bounty conditions". The first is "Privilege Escalation", because he can skip "Posting System" rules. And the second is "Circumvention Platform Permission Models", because he skipped the permission models. But they didn't admit it. Then he got this email:


"Hi Symbian,
As said we don't consider this a security vulnerability. I am closing out this ticket now.
Thanks,
Emrakul
Security
Facebook"

Then he added "OK, that's not a big deal. I'll use this feature on my profile till they close it and i also have a PoCs. And I'll sell some statistics to the big companies, and if they like and they pay  I can install this feature on their fan pages as well. And that is not illegal and not breaking the Whitehat rules, as the security team said in their reply in email number #1."


Proof of concepts:-


An Poll Question Example on his personal page-

http://goo.gl/SPT1JF

An Poll Question Example on his personal Account-

http://goo.gl/rjBgDw

His Contact- SymbianSyMoh.com


It seems the Facebook security team is making thing's difficult for the bounty hunters. Last time they did with Palestine web developer and hacker, 'Khalil Shreateh', He was forced to post vulnerability details on Mark Zuckerberg (Facebook Founder) Timeline to prove his point, after the Facebook Security Team failed to recognize his critical vulnerability three times.

Popular Post

Powered by Blogger.