Error in Facebook code allowed attackers to delete live streams
The case was revealed on April 17th by security expert Ahmad Talahmeh. An error in the code of the Facebook allowed attackers to delete lives (live broadcasts) from the platform without the account owner knowing.
The researcher explained that the vulnerability allowed live videos were deleted as if the action had been carried out by the page owner himself.
In reality, the bug causes the video to have its length cut to five milliseconds, according to Talahmeh. “Cutting the video to five milliseconds will make it 0 seconds long and the owner will not be able to undo it,” the expert said.
Problem fixed
As lives, on Facebook and other platforms, gained traction during the Covid-19 pandemic, both among ordinary users and among companies, organizations and influencers. After a broadcast is ended, the page owner can edit the video to implement cuts. This tool was exploited by scammers. To do this, they only needed to obtain the live ID.
After the problem was discovered on September 25, 2020, Facebook analyzed it and fixed it. As a reward, Talahmeh received $11 from BountyCon and another nearly $5 from Facebook itself. The case only became public after the social network released a patch to fix the problem.
In addition to live streams, the expert also pointed out another security error on Facebook. The social network launched a system to help businesses adapt to the pandemic. The page now allows for clearer indication of opening hours, delivery points and physical stores of products. However, the update for this special page and its settings could be done by those with analyst permission, who could normally only read the content, and not change it. This second flaw has also been fixed.
Through which channels you reach those people, classic and out of the box. Z
Image: vichie81/Pixabay/CC