Skip to content
The Cyber Security Place

Software

Facebook XSS could have allowed attackers to take over users’ accounts

Reported by securityaffairs.co

The security expert Jack Whitton reported a critical XSS vulnerability to Facebook that could be exploited by hackers to take over users’ Facebook accounts. The researchers reported the flaw to Facebook in July 2015, and the company fixed the problem in just 6 hours.

Facebook rewarded $7,500 the expert for the flaw under its bounty program.

The researcher’s attack method has two main aspects: one related to content types and a DNS issue.

Read the full article at securityaffairs.co