Discovered a security vulnerability on the Facebook platform, earned $100,000!

A researcher discovered a security vulnerability that allowed for the takeover of the server hosting Facebook's advertising platform. Meta awarded him $100,000 for discovering the issue.

12punto

A security researcher named Ban Sadeghipour discovered a significant security vulnerability while working at Meta. While examining Facebook's advertising platform, Sadeghipour identified a security flaw that allowed for command execution on the internal servers to which the platform was connected. This vulnerability made it possible to access internal company data and take control of the server in a way that would normally be unauthorized.

$100,000 REWARD AWARDED BY META

Sadeghipour promptly reported this security vulnerability, which could have led to major consequences, to Facebook's parent company, Meta. Meta evaluated the issue quickly and provided a solution within just 1 hour. Sadeghipour was awarded $100,000 for the security vulnerability he discovered.

According to the researcher, the issue stemmed from a server that Facebook used to create and serve advertisements, which contained a previously patched bug in the Chrome browser. Sadeghipour managed to gain access to the server by exploiting this bug in the Chrome browser.

It was emphasized that this security vulnerability could have been quite dangerous because it was part of the internal infrastructure and advertising platforms carry a large amount of sensitive data. The researcher noted that similar security vulnerabilities could exist at other companies.