Meta✴ paid $100,000 to independent cybersecurity specialist Ben Sadeghipour for discovering a serious vulnerability in the platform. While analyzing the ad serving system, Sadeghipour found a flaw that allowed him to execute a command in a private part of Facebook’s server infrastructure✴, effectively gaining full control of the server.

Image source: Shutter Speed ​​/ Unsplash

As reported by TechCrunch, the vulnerability was associated with one of the servers used by Facebook✴ to create and display ads. This server was affected by a previously known and fixed bug in the Chrome browser, which Facebook✴ uses in its advertising system. Sadeghipour explained that by using a light version of the Chrome browser, launched through a terminal, he was able to interact with the company’s internal servers and gain access to manage them as an administrator.

«I assumed that this was a critical vulnerability that was worth fixing since it was located right inside your infrastructure,” Sadeghipour wrote in his email to Meta✴. The company quickly responded to the situation and asked the researcher to refrain from further testing until the problem was resolved. The fix took only one hour.

Sadeghipour also emphasized the danger of the discovered error. While he did not test all possible functionality that could be exploited from within Facebook’s infrastructure✴, he did caution that the vulnerability could potentially allow access to other sites and systems within the company’s infrastructure. “Using a remote code execution vulnerability, you can bypass restrictions and directly extract data both from the server itself and from other devices to which it is connected,” he explained.

Meta✴ refused to provide a comment at the request of journalists, but the fact that the bug was fixed was confirmed. Sadeghipour also added that similar problems exist with other companies whose advertising platforms he tested.

admin

Share
Published by
admin

Recent Posts

Xiaomi will release a tablet based on the Qualcomm Snapdragon 8 Elite chip this year

Flagship Android tablets powered by the latest and greatest Qualcomm microprocessors are quite rare, while…

2 hours ago

Cooler Master introduced an innovative cooler – it will be exclusive to ready-made PCs

According to online sources, Cooler Master is working on creating its own video card of…

3 hours ago

The updated Tesla Model Y is officially presented in China and a number of other Asian markets

Yesterday's appearance of spy shots of the updated version of the Tesla Model Y turned…

3 hours ago

AMD explained the shortage of Ryzen 9 9800X3D processors: Intel and its terrible Arrow Lake processors are to blame

AMD representatives commented on the ongoing shortage of the flagship Ryzen 9 9800X3D processor, which…

4 hours ago

AMD explained why the Ryzen 9 9950X3D received only one 3D V-Cache die, and not two

One of the key announcements from AMD's CES 2025 presentation, held on January 6, was…

9 hours ago

The US will simplify the connection of AI data centers to geothermal energy sources

The outgoing US government in the coming days intends to make it easier to obtain…

9 hours ago