Responsible disclosure: retrieving a user's private Facebook friends.
Read OriginalThis technical article explains a security vulnerability where an attacker could retrieve a user's private Facebook friend list by signing up for Instagram with the victim's email address. It details the flaw's mechanism, involving the linking of accounts and features available before email confirmation. The post includes the responsible disclosure timeline to Facebook and the resulting $3000 bounty award.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser