Category: IT|Jan 21, 2017 | Author: Admin

How This Hacker Broke Facebook With ImageMagick Flaw And Won $40k Reward

Share on

A widely-reported flaw in ImageMagick, an open source tool, was used by a hacker to crack Facebook’s servers with remote code execution. The bug, possibly, allows the attacker to upload malicious images that help in the compromise. Bug hunger Andrew Leonov claims that Facebook issued him $40,000 bug bounty in last October. We’ve contacted Facebook for confirmation and further update.

A widely-reported flaw in ImageMagick, an open source tool, was used by a hacker to crack Facebook’s servers with remote code execution. The bug, possibly, allows the attacker to upload malicious images that help in the compromise. Bug hunger Andrew Leonov claims that Facebook issued him $40,000 bug bounty in last October. We’ve contacted Facebook for confirmation and further update.

ImageMagick flaw was found in the end of April, 2016. As many processing plugins depend on the ImageMagick library, this issue had a widespread impact. It looks like a security researcher has gained remote code execution on its servers using ImageMagick flaw in recent times. 

Bug hunger Andrew Leonov has detailed a blog post and disclosed how he gained remote code execution on Facebook’s servers. He has written all the details, except the sensitive proof-of-concept exploit.

“For full proof that exploit works I provided Facebook security team with result of cat /proc/version output which is not going to publish here,” Leonov writes.

ImageMagick is an open source tool used by developers and designers to resize, crop, and tweak pictures.

As mentioned above, last year it was found that the tool can be abused to allow the hackers to upload malicious images, which can be used to grant remote code execution. This can further result in data theft, exfiltration, and other types of compromises.

Leonov claims that Facebook has paid him $40,000 for his vulnerability report. As of now, Facebook’s highest bounty figure is $33,500, which was awarded to Reginaldo Silva.

According to Leonov’s post, he filed the initial report on 16 October and his $40,000 reward was issued on 28 Oct.

Fossbytes has contacted Facebook for a confirmation and further update. For further details, read Leonov’s blog post here.

Sponsored Ads:

Comments:


Siri can no longer tell the clock

Category: Apple|May 4, 2024 | Author: Admin

Struggling with VPN

Category: Microsoft|May 3, 2024 | Author: Admin

This is how Huawei tricked its way into the US

Category: IT|May 2, 2024 | Author: Admin

Edge 125 arrives in Beta with sleeping tab improvements and other changes

Category: IT|May 1, 2024 | Author: Admin

Now the iPad opens

Category: Apple|Apr 30, 2024 | Author: Admin

Woke up locked out of Apple ID on iPhone

Category: Apple|Apr 29, 2024 | Author: Admin

Google has a hidden collection of highly-addictive retro games

Category: Google|Apr 28, 2024 | Author: Admin

Google is officially a $2 trillion company

Category: Google|Apr 27, 2024 | Author: Admin

Snowden: “DO NOT use Reddit!”

Category: IT|Apr 26, 2024 | Author: Admin

Popular Google app used by millions set to close in a few weeks

Category: Google|Apr 25, 2024 | Author: Admin

Cheeky, YouTube!

Category: Google|Apr 24, 2024 | Author: Admin

This is the date Apple will reveal new iPads

Category: Apple|Apr 23, 2024 | Author: Admin

Only possible with VPN

Category: IT|Apr 22, 2024 | Author: Admin

Apple sidles into sideloading in the EU

Category: Apple|Apr 21, 2024 | Author: Admin

Report: Microsoft-OpenAI ownership might get conditional OK from EU regulators

Category: IT|Apr 20, 2024 | Author: Admin
more