Facebook security hacker proves point - by posting to Mark Zuckerburg's wall

Well, that's midly embarassing.

Facebook security hacker proves point - by posting to Mark Zuckerburg's wall

Have you ever had that situation where you're in touch with a customer service rep just doesn't seem to get your problem, no matter how many times you explain it? So you end up going over their head to their boss?

Well, that's kinda what happened when Khalil Shreateh had to prove that Facebook had a security bug - and he did it by hacking his way on to company founder Mark Zuckerburg's wall.

“Sorry for breaking your privacy [to post] to your wall, I has no other choice to make after all the reports I sent to Facebook team," the Palestinian hacker wrote on Zuck's wall, which is for his friends only - something he really shouldn't have been able to do.

See, Facebook and other big tech companies run a bounty system, where people who discover security holes and report them get paid cash - at least US $500, and maybe a whole lot more - as encouragement to report them.

Technology news site Techcrunch, though, has the full story, where Shreateh tried to report it, only for a clueless security team member on the other side to keep telling him there was no problem.

"In his initial report of the bug, Khalil demonstrated that he was able to post on anyone’s wall by submitting a link to a post he’d made on the wall of Sarah Goodin (a college friend of Zuck’s, and the first woman on Facebook," Techcrunch reports.

"Unfortunately, the member of the Facebook Security team who clicked the link wasn’t friends with Goodin, whose wall was set to be visible to friends only. As a result, they couldn’t see Khalil’s post."

So, the security team member couldn't seem to understand how this worked on Facebook - not a good sign - and kept telling Shreateh there was no bug. So, after a couple of attempts to get the idea across, Shreateh posted right to the company founder's wall to prove his point.

Apparently he got a reply in the next few minutes.

But, sadly, it looks like the hacker won't get his prize, because he broke Facebook's rules in exposing the security flaw - because he attacked a user's wall to get his point across. Sure, in this case the user is the company founder, but Facebook says it can't reward that kind of thing.

Techcrunch has the full story.

more courts articles

Laurence Fox ordered to pay €210,000 in libel damages Laurence Fox ordered to pay €210,000 in libel damages
Former DUP leader Jeffrey Donaldson arrives at court to face sex charges Former DUP leader Jeffrey Donaldson arrives at court to face sex charges
Case against Jeffrey Donaldson to be heard in court Case against Jeffrey Donaldson to be heard in court

More in this section

Smartwatch with health app. Glowing neon icon on brick wall background Health watch: How much health data is healthy? 
Cork's wild salmon warrior Sally Ferns Barnes looks to the future Cork's wild salmon warrior Sally Ferns Barnes looks to the future
(C)2024 Disney. Disneyland Paris – Disneyland Hotel Re-Opening Watch: Iconic Disneyland Paris hotel re-opens after two year renovation
ieParenting Logo
Writers ieParenting

Our team of experts are on hand to offer advice and answer your questions here

Your digital cookbook

ieStyle Live 2021 Logo
ieStyle Live 2021 Logo

IE Logo
Outdoor Trails

Discover the great outdoors on Ireland's best walking trails

IE Logo
Outdoor Trails

Lifestyle
Newsletter

The best food, health, entertainment and lifestyle content from the Irish Examiner, direct to your inbox.

Sign up
Cookie Policy Privacy Policy Brand Safety FAQ Help Contact Us Terms and Conditions

© Examiner Echo Group Limited