Monday, February 8, 2016

Overwriting/Removing Cover Photos on Facebook Event Pages

This blog post is about an Insecure Direct Object Reference vulnerability in Facebook Events which an attacker could have remove/overwrite your Event Cover Photo just by replacing his Event id with yours in Event editing request.



Vulnerability Description

Insecure Direct Object References occur when an application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass authorization and access resources in the system directly, for example database records or files. 
Insecure Direct Object References allow attackers to bypass authorization and access resources directly by modifying the value of a parameter used to directly point to an object. Such resources can be database entries belonging to other users, files in the system, and more. This is caused by the fact that the application takes user supplied input and uses it to retrieve an object without performing sufficient authorization checks. Reference: OWASP

Steps to Reproduce


1. Create an Event, right click edit and inspect element


2. Change the event_id's values to victim's Event id so attacker can request to edit victim's Event


3. To Overwrite, upload new photo then save
4. To Remove, click the "x" then save

Attacker successfully removed the cover photo without victim's knowledge 



as well as overwrite the cover photo 

FIX

Now, you can only overwrite/remove your own cover.





Disclosure Timeline


Jan 11, 2016 - Report Sent
Jan 13, 2016 - Escalation by Facebook
Jan 14, 2016 - Patched by Facebook
Jan 20, 2016 - Bounty Awarded by Facebook

378 comments:

  1. congrats sir, 5 years na kayo nasa whitehat list haha

    ReplyDelete
  2. Congrats po at salamat sa pag share! :-) isa kang alamat!

    ReplyDelete
  3. Imba ka gudman Mr. Roy Totdoe daw kami didi mga taga Calbayog Samar hehe God Bless po

    ReplyDelete
  4. Appaustic is an app development company helping start ups, enterprises in effective interaction with their clients. We are developing smart apps for iOS and Android. We have experts for facebook app development too.

    ReplyDelete
  5. Do you need free Twitter Followers?
    Did you know you can get them AUTOMATICALLY & ABSOLUTELY FOR FREE by getting an account on Like 4 Like?

    ReplyDelete
  6. This comment has been removed by the author.

    ReplyDelete
  7. This comment has been removed by the author.

    ReplyDelete
  8. Hi, Great.. Tutorial is just awesome..It is really helpful for a newbie like me.. I am a regular follower of your blog. Really very informative post you shared here. Kindly keep blogging.
    Data Science training in Chennai | Data science training in bangalore
    Data science training in pune| Data science online training
    Python training in Kalyan nagar

    ReplyDelete
  9. You’ve written a really great article here. Your writing style makes this material easy to understand.. I agree with some of the many points you have made. Thank you for this is real thought-provoking content
    java training in jayanagar | java training in electronic city

    java training in chennai | java training in USA

    ReplyDelete
  10. Thanks for the informative article. This is one of the best resources I have found in quite some time. Nicely written and great info. I really cannot thank you enough for sharing.
    python training in velachery
    python training institute in chennai

    ReplyDelete
  11. Your information's are very much helpful for me to clarify my doubts.
    keep update more information's in future.
    Java Institutes in bangalore
    Java Institute in T nagar
    Java Training in Sholinganallur

    ReplyDelete
  12. Very useful assistance in this particular article! It's the net worth gucci mane small improvements that make net worth eminem the greatest changes. net beyonce Thanks for discussing! net adam sandler This article net jerry seinfeld you've discussed here very awesome. I really like and appreciated your work. I study deeply your net kevin hart report, the items you have stated in this information are net triple h helpful net john cena I have never had a picked radish or green vegetable that I'm aware of - but following seeing these net david bowielovely pictures, net julia louis dreyfus I know I want to!

    ReplyDelete
  13. Nice and good post. This is a wonderful article, Given so much info in it, keep sharing.

    Data Science Courses in Bangalore

    ReplyDelete
  14. Its as if you had a great grasp on the subject matter, but you forgot to include your readers. Perhaps you should think about this from more than one angle.
    data science courses training
    data analytics certification courses in Bangalore
    ExcelR Data science courses in Bangalore

    ReplyDelete
  15. You know your projects stand out of the herd. There is something special about them. It seems to me all of them are really brilliant!
    data analytics course malaysia

    ReplyDelete
  16. I really enjoy simply reading all of your weblogs. Simply wanted to inform you that you have people like me who appreciate your work. Definitely a great post. Hats off to you! The information that you have provided is very helpful.




    BIG DATA COURSE MALAYSIA

    ReplyDelete
  17. Excellent Blog! I would like to thank for the efforts you have made in writing this post. I am hoping the same best work from you in the future as well. I wanted to thank you for this websites! Thanks for sharing. Great websites!digital marketing course in singapore

    ReplyDelete
  18. This entire post absolutely ROCKS! Thank you for all the hard work you put into it. It really shows. Click for more, Click for more, Click for solution, Click for solution, Click for solution.

    ReplyDelete
  19. After reading your article I was amazed. I know that you explain it very well. And I hope that other readers will also experience how I feel after reading your article.
    seo certification course

    ReplyDelete
  20. Your blog was absolutely fantastic! Great deal of great information & this can be useful some or maybe the other way. Keep updating your blog,anticipating to get more detailed contents.

    Did you now number one online casino:
    sbobet
    เอสบีโอเบท
    sbobetมือถือ
    sbobetthai

    ReplyDelete
  21. Hi,
    Good job & thank you very much for the new information, i learned something new. Very well written. It was sooo good to read and usefull to improve knowledge. Who want to learn this information most helpful. One who wanted to learn this technology IT employees will always suggest you take hadoop training in bangalore. Because data science course in pune is one of the best that one can do while choosing the course.

    ReplyDelete
  22. I Got Job in my dream company with decent 12 Lacks Per Annum salary, I have learned this world most demanding course out there in the current IT Market from the Hkbk group of institutions experts who helped me a lot to achieve my dreams comes true. Really worth trying

    ReplyDelete
  23. Hi, yup this post is really good and I have learned lot of things from it about blogging.
    thanks.
    sbobet88

    ReplyDelete
  24. Awesome..I read this post so nice and very imformative information...thanks for sharing Awesome..I read this post so nice and very imformative information...thanks for sharing
    Click here for data science course
    Click here for data science course

    ReplyDelete
  25. Great Article. Thank you for sharing! Really an awesome post for every one.

    IEEE Final Year projects Project Centers in Chennai are consistently sought after. Final Year Students Projects take a shot at them to improve their aptitudes, while specialists like the enjoyment in interfering with innovation. For experts, it's an alternate ball game through and through. Smaller than expected IEEE Final Year project centers ground for all fragments of CSE & IT engineers hoping to assemble. Final Year Project Domains for IT It gives you tips and rules that is progressively critical to consider while choosing any final year project point.

    JavaScript Training in Chennai

    JavaScript Training in Chennai


    ReplyDelete
  26. This comment has been removed by the author.

    ReplyDelete
  27. This comment has been removed by the author.

    ReplyDelete
  28. Thanks for sharing your innovative ideas to our vision. I have read your blog and I gathered some new information through your blog. Your blog is really very informative and unique. Keep posting like this. Awaiting for your further update.If you are looking for any Hadoop related information, please visit our website Hadoop training institute in bangalore

    ReplyDelete
  29. Truly, this article is really one of the very best in the history of articles. I am a antique ’Article’ collector and I sometimes read some new articles if I find them interesting. And I found this one pretty fascinating and it should go into my collection. Very good work!
    data analytics course in bangalore
    data science interview questions

    ReplyDelete
  30. I feel very grateful that I read this. It is very helpful and very informative and I really learned a lot from it.

    data analytics courses

    data science interview questions

    business analytics courses

    data science course in mumbai

    ReplyDelete
  31. Nice blog,I understood the topic very clearly,And want to study more like this.
    Data Scientist Course

    ReplyDelete
  32. I understood the topic very clearly,And want to study more like this.
    Whatsapp group links

    ReplyDelete
  33. Cool stuff you have and you keep overhaul every one of us.
    digital marketing course pune

    ReplyDelete
  34. Attend The Data Science Courses From ExcelR. Practical Data Science Courses Sessions With Assured Placement Support From Experienced Faculty. ExcelR Offers The Data Science Courses.
    Data Science Courses
    Data Science Interview Questions

    ReplyDelete
  35. wonderful article. Very interesting to read this article.I would like to thank you for the efforts you had made for writing this awesome article. This article resolved my all queries.
    Data science Interview Questions

    ReplyDelete
  36. wonderful article. Very interesting to read this article.I would like to thank you for the efforts you had made for writing this awesome article. This article resolved my all queries.
    Data science Interview Questions
    Data Science Course

    ReplyDelete
  37. ยินดีต้อนรับสู่ g-win88.com เกมคาสิโนออนไลน์อันดับ 1 ที่ดีที่สุดในประเทศไทยและเอเชีย!

    ⮚ รับโบนัสฟรี 100% สำหรับสมาชิกใหม่
    ⮚ โปรโมชั่น แทงบอลออนไลน์ รับค่าคอม x3
    ⮚ โปรโมชั่น ลูกค่าบาคาร่า รับคืนยอดเสีย ฟรีๆ 10%

    ฝาก-ถอน โอนไว 24 ชั่วโมง⏰, ได้เงินชัว ไม่มีโกง 💯%, โปรโมชั่นดีดีไม่เหมือนที่อื่นแน่นอน

    ╔══════════════════╗
    ♛สมัครวันนี้เลย ADD LINE : https://lin.ee/1ZdZara
    ☎️Call Center บริการตลอด 24 ชม. 0929553889
    💋💋รับสิทธิ์ ฟรี!! จำนวนจำกัด💋💋
    ╚══════════════════╝

    ReplyDelete
  38. wonderful article. Very interesting to read this article.I would like to thank you for the efforts you had made for writing this awesome article. This article resolved my all queries. keep it up.
    data analytics course in Bangalore

    ReplyDelete
  39. Pretty article! I found some useful information in your blog....

    so here we provide,

    We provide you with flexible services and complete hybrid network solutions. It can provide your organisation with exceptional data speeds, advanced external security protection, and high-resilience by leveraging the latest SD-WAN and networking technologies to monitor, manage and strengthening your organisation’s existing network devices.

    https://www.quadsel.in/networking/>
    https://twitter.com/quadsel/
    https://www.linkedin.com/company/quadsel-systems-private-limited/
    https://www.facebook.com/quadselsystems/

    #quadsel #network #security #technologies #managedservices #Infrastructure #Networking #OnsiteResources #ServiceDeskSupport #StorageServices #WarrantyAMCServices #datacentersolutions #DataCenterBuild #EWaste #InfraConsolidation #DisasterRecovery #NetworkingServices #ImagingServices #MPS #Consulting #WANOptimisation #enduserservices

    ReplyDelete
  40. Very interesting to read this article.I would like to thank you for the efforts you had made for writing this awesome article. This article inspried me to read more. keep it up.
    Correlation vs Covariance

    ReplyDelete
  41. What a great article!. I am bookmarking it to read it over again after work. It seems like a very interesting topic to write about.
    SAP training in Kolkata
    Best SAP training in Kolkata
    SAP training institute in Kolkata

    ReplyDelete
  42. There are many aspects of this article on which I concur with you. You have generated synapses in my brain not used often. Thank you for getting my neurons jumping.
    SAP training in Kolkata
    SAP training Kolkata
    Best SAP training in Kolkata
    SAP course in Kolkata
    SAP training institute Kolkata

    ReplyDelete
  43. Do you have a website for your business? Are you work hard for your website to rank on Google's top position but your website didn't show anywhere? It is because you didn't optimize your website's SEO properly.great jobs.
    Ai & Artificial Intelligence Course in Chennai
    PHP Training in Chennai
    Ethical Hacking Course in Chennai Blue Prism Training in Chennai
    UiPath Training in Chennai

    ReplyDelete
  44. Very interesting blog. Many blogs I see these days do not really provide anything that attracts others, but believe me the way you interact is literally awesome.You can also check my articles as well.

    Data Science In Banglore With Placements
    Data Science Course In Bangalore
    Data Science Training In Bangalore
    Best Data Science Courses In Bangalore
    Data Science Institute In Bangalore

    Thank you..

    ReplyDelete
  45. Very interesting to read this article.I would like to thank you for the efforts you had made for writing this awesome article. This article inspired me to read more. keep it up.
    Correlation vs Covariance
    Simple linear regression

    ReplyDelete
  46. This Was An Amazing ! I Haven't Seen This Type of Blog Ever ! Thankyou For Sharing, data science courses

    ReplyDelete
  47. Great knowledge, do anyone mind merely reference back to it Data Science Course in Hyderabad

    ReplyDelete
  48. Get daily updated deals and offer and save big on your purchase
    Tracedeals's live search is helping to find the best deals compared to other online stores.

    Today Mobile Offers
    Mobile Phones
    Mobile Offers In Flipkart
    Latest Mobile Offers
    Mobile Offers In India
    Realme Mobile Offers
    Mobile Phones Under 10,000
    Amazon Mobile Offers
    Flipkart Mobile Offers
    Up Coming Mobile Offers


    Very detailed and informative!!
    Keep On Sharing....

    ReplyDelete
  49. This is a wonderful article, Given so much info in it, These type of articles keeps the users interest in the website, and keep on sharing more ... good luck.

    data science interview questions

    ReplyDelete
  50. Very interesting to read this article.I would like to thank you for the efforts you had made for writing this awesome article. This article inspired me to read more. keep it up.
    Correlation vs Covariance
    Simple linear regression
    data science interview questions

    ReplyDelete
  51. I like viewing web sites which comprehend the price of delivering the excellent useful resource free of charge. I truly adored reading your posting. Thank you!

    data science interview questions

    ReplyDelete
  52. I have express a few of the articles on your website now, and I really like your style of blogging. I added it to my favorite’s blog site list and will be checking back soon…
    Machine Learning Courses in Pune Thank you for the post. I will definitely comeback.

    ReplyDelete
  53. Amazing Article ! I would like to thank you for the efforts you had made for writing this awesome article. This article inspired me to read more. keep it up.
    Correlation vs Covariance
    Simple Linear Regression
    data science interview questions
    KNN Algorithm

    ReplyDelete
  54. I have to search sites with relevant information on given topic and provide them to teacher our opinion and the article.

    Simple Linear Regression

    Correlation vs Covariance

    ReplyDelete
  55. This professional hacker is absolutely reliable and I strongly recommend him for any type of hack you require. I know this because I have hired him severally for various hacks and he has never disappointed me nor any of my friends who have hired him too, he can help you with any of the following hacks:

    -Phone hacks (remotely)
    -Credit repair
    -Bitcoin recovery (any cryptocurrency)
    -Make money from home (USA only)
    -Social media hacks
    -Website hacks
    -Erase criminal records (USA & Canada only)
    -Grade change
    -funds recovery

    Email: onlineghosthacker247@ gmail .com

    ReplyDelete
  56. Amazing Article ! I would like to thank you for the efforts you had made for writing this awesome article. This article inspired me to read more. keep it up.
    Correlation vs Covariance
    Simple Linear Regression
    data science interview questions
    KNN Algorithm
    Logistic Regression explained

    ReplyDelete
  57. Amazing Article ! I would like to thank you for the efforts you had made for writing this awesome article. This article inspired me to read more. keep it up.
    Simple Linear Regression
    Correlation vs covariance
    data science interview questions
    KNN Algorithm
    Logistic Regression explained

    ReplyDelete
  58. Attend The Data Analyst Course From ExcelR. Practical Data Analyst Course Sessions With Assured Placement Support From Experienced Faculty. ExcelR Offers The Data Analyst Course.
    Data Analyst Course

    ReplyDelete
  59. very well explained .I would like to thank you for the efforts you had made for writing this awesome article. This article inspired me to read more. keep it up.
    Simple Linear Regression
    Correlation vs covariance
    data science interview questions
    KNN Algorithm
    Logistic Regression explained

    ReplyDelete
  60. very well explained. I would like to thank you for the efforts you had made for writing this awesome article. This article inspired me to read more. keep it up.
    Logistic Regression explained
    Correlation vs Covariance
    Simple Linear Regression
    data science interview questions
    KNN Algorithm

    ReplyDelete
  61. Attend The Data Analytics Courses From ExcelR. Practical Data Analytics Courses Sessions With Assured Placement Support From Experienced Faculty. ExcelR Offers The Data Analytics Courses.
    Data Analytics Courses

    ReplyDelete
  62. very well explained. I would like to thank you for the efforts you had made for writing this awesome article. This article inspired me to read more. keep it up.
    Logistic Regression explained
    Correlation vs Covariance
    Simple Linear Regression
    data science interview questions
    KNN Algorithm

    ReplyDelete
  63. The great thing about this post is quality information. I always like to read amazingly useful and quality content.
    Your article is amazing, thank you for sharing this article.

    Mobile Phone Offers Today
    Mobile Phone Offers
    today mobile offers
    diwali mobile offers
    mobile offers for diwali

    Very detailed and informative!!
    Keep On Sharing....

    ReplyDelete
  64. very well explained. I would like to thank you for the efforts you had made for writing this awesome article. This article inspired me to read more. keep it up.
    Logistic Regression explained
    Correlation vs Covariance
    Simple Linear Regression
    data science interview questions
    KNN Algorithm
    Bag of Words Python

    ReplyDelete
  65. Insecure Direct Object References occur when an application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass authorization and access resources in the system directly, for example database records or files. polycotton sheets , queen bed comforter set , alkaram bed sheets , fancy nancy twin bed set , buy duvet covers online , vicky razai factory , 3 piece sofa covers , velvet sheet set

    ReplyDelete


  66. Nice article and thanks for sharing with us. Its very informative



    Plots in THIMMAPUR

    ReplyDelete
  67. iot training in chennai - IoT Training in Chennai - IoT is one of the technologies which has a lot of scope at the very same time very less number of skilled employees in this technology which means this particular technology will give a huge success rate. Join the Best IOT Training Institute in Chennai now.

    Devops training Institute in Chennai - DevOps a combination of Development and operations has an better career .Jobs opportunities are there from startup companies to big mnc. Start to learn DevOps technology soon and secure your job now.

    blue prism training in Chennai - If you choose to learn the blue prism or automation tool you are supposed to have the programming language. start to learn the blue prism training from the Best Blue prism Training Institute in Chennai.

    uipath training in Chennai - UI path technology is one of the fastest developing fields which has a lot of job opportunities such as software developer, Programmer and lot more. Join the Best Uipath Training Institute in Chennai.

    microsoft azure training in chennai -Microsoft azure technology is growing and soon it will be competitive aws. So students who start to learn Microsoft azure now will be well - paid in the future. Start to learn Microsoft azure training in Chennai.

    Chennai IT Training Center

    ReplyDelete
  68. I finally found great post here.I will get back here. I just added your blog to my bookmark sites. thanks.Quality posts is the crucial to invite the visitors to visit the web page, that's what this web page is providing.Data Analytics Course

    ReplyDelete
  69. Great post i must say and thanks for the information. Education is definitely a sticky subject. However, is still among the leading topics of our time. I appreciate your post and look forward to more.
    Data Science Course in Bangalore

    ReplyDelete
  70. Thanks for posting the best information and the blog is very informative.Data science course in Faridabad

    ReplyDelete
  71. This professional hacker is absolutely reliable and I strongly recommend him for any type of hack you require. I know this because I have hired him severally for various hacks and he has never disappointed me nor any of my friends who have hired him too, he can help you with any of the following hacks:

    -Phone hacks (remotely)
    -Credit repair
    -Bitcoin recovery (any cryptocurrency)
    -Make money from home (USA only)
    -Social media hacks
    -Website hacks
    -Erase criminal records (USA & Canada only)
    -Grade change
    -funds recovery

    Email: onlineghosthacker247@ gmail .com

    ReplyDelete
  72. Thanks for posting the best information and the blog is very informative.Data science course in Faridabad

    ReplyDelete
  73. https://brtiamerica.blogspot.com/2013/12/installing-print-driver-for-hp.html?showComment=1601129743449#c880941674498067109
    Chennai IT Training Center
    Artificial Intelligence training in chennai - Basically AI Artificial Intelligence is a programming which is created for robots to think and work on there own without the help of humans.

    RPA Training Institute in Chennai - RPA is useful in making complex decision by collaborating with Artificial Intelligence. And it will also contribute to the market of Big data and IOT. Join the Best RPA Training Institute in Chennai now.

    Load runner training in Chennai - Load runner is an software testin tool. It is basically used to test application measuring system behaviour and performance under load. Here comes an Opportunity to learn Load Runner under the guidance of Best Load Runner Training Institute in Chennai.

    ReplyDelete
  74. Outstanding blog appreciating your endless efforts in coming up with an extraordinary content. Which perhaps motivates the readers to feel excited in grasping the subject easily. This obviously makes every readers to thank the blogger and hope the similar creative content in future too.
    360DigiTMG Data Analytics Course

    ReplyDelete
  75. Wonderful blog found to be very impressive to come across such an awesome blog. I should really appreciate the blogger for the efforts they have put in to develop such an amazing content for all the curious readers who are very keen of being updated across every corner. Ultimately, this is an awesome experience for the readers. Anyways, thanks a lot and keep sharing the content in future too.

    Digital Marketing training in Bhilai

    ReplyDelete
  76. Thanks for posting the best information and the blog is very helpful.Data science course in Varanasi

    ReplyDelete
  77. It is amazing and wonderful to visit your site. Thanks for sharing information; this is useful to student....

    SASVBA provides the best R Programming Training In Delhiusing the latest development environment and framework in Delhi. We constantly update our program to reflect the latest industry trends. SASVBA is one of the top deep learning teaching institutes at NCR in Delhi that assists students in interviewing tech giants. We educate both college students and schoolchildren.

    FOR MORE INFO:

    ReplyDelete
  78. Everything is your post going to be alright. Are we really being honest
    Computer Full Form and Job Information
    OTT Full Form

    ReplyDelete
  79. K9 Security England provides high quality, social dogs that are raised and trained specifically to obey and protect their owners. Similar to a child enrolled in martial arts classes, our pups start training at a very young age. By the time they're adults, just like the child, our dogs will be confident, disciplined, obedient, respectful and very well capable of defending on command. https://www.k9securityengland.com/

    ReplyDelete
  80. Fantasy Power11 is an online cricket app. You can play fantasy cricket games and other games on the app. If you are a
    cricket fan and love to read articles related to it, you will also love this live cricket online app.
    The app is available for Android and is one of the best cricket games for Android. You can play cricket online on the app.
    play cricket online

    ReplyDelete
  81. This is awesome, thanks for the share. Also, visit our website if you are looking to purchase logo:

    Purchase Logo

    ReplyDelete
  82. Great to become visiting your weblog once more, it has been a very long time for me. Pleasantly this article i've been sat tight fosuch a long time. I will require this post to add up to my task in the school, and it has identical subject along with your review. Much appreciated, great offer. data science course in nagpurr

    ReplyDelete
  83. I recently came across your article and have been reading along. I want to express my admiration of your writing skill and ability to make readers read from the beginning to the end.
    Python Classes in Pune

    ReplyDelete
  84. I found your web site via Google whilst searching for a similar subject, your website came up, it looks good.Really very happy to say,your post is very interesting to read.I never stop myself to say something about it.You’re doing a great job.Your post is owsum,Keep it up.countdown timer

    ReplyDelete
  85. kya aap islamic information zero to hero sikhna chahte hai to Namaz Quran website ke sath jude jao waha pe apko daily new post islamic knowledge ka milega.

    ReplyDelete
  86. IGRS Telangana portal is the all type services provide in telangana state

    ReplyDelete
  87. I am a new user of this site, so here I saw several articles and posts published on this site, I am more interested in some of them, will provide more information on these topics in future articles.
    data science course in london

    ReplyDelete