Friendly hacker finds backdoor in Facebook

Facebook laptop

Facebook's internal systems were compromised and a server containing staff details was hit by malware opening up a backdoor that allowed usernames and passwords to be extracted – although this issue was reported by a bug bounty hunter and has since been fixed.

Orange Tsai was the exploit hunter in question, and he discovered the vulnerability in the Facebook server back in February, then reported it to the social network's security team.

As Betanews reports, Tsai hacked into said Facebook server and discovered password-thieving PHP scripts – obviously a very serious issue. So it isn't surprising that he received a large payment for this bit of white hat hacking, and a week after reporting the issue, he was told he'd be rewarded to the tune of $10,000 (around £7,000, or AU$13,000).

It's a worrying glimpse into how even web giants like Zuckerberg's firm are open to being exploited by just a single individual with some hacking smarts.

Note that this was a staff server and the backdoor was pilfering Facebook staff member credentials (as opposed to actual users of the social network), and Tsai says he found around 300 logged credentials dated to the first week of February when he pulled off his hack.

Not malicious

The Facebook security engineer, Reginaldo Silva, who dealt with the case said the backdoor had actually been put there by another bounty hunting security researcher, so this too was a white hat action of sorts, and apparently not a malicious attack.

Silva noted: "Neither of them were able to compromise other parts of our infrastructure, so the way we see it, it's a double win: two competent researchers assessed the system, one of them reported what he found to us and got a good bounty, none of them were able to escalate access."

According to Tsai, the other hacker made attempts to probe further and access Facebook's internal mail system, for example, but wasn't successful in these endeavours. Tsai also noted there were two periods of time when the backdoor was utilised last year, and he muses whether this might have been different hackers doing so – although Facebook clearly believes this was just one person.

Of course, the hole has now been patched up and Facebook conducted an extensive forensics investigation over the past couple of months, which was completed last week, leaving Tsai free to post about and discuss the issue.

TOPICS

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening