Facebook Rewards Expert with $33,500 for Remote Code Execution Flaw
Facebook has rewarded Brazilian computer engineer and security researcher Reginaldo Silva with $33,500 (€25,000) for finding and reporting a remote code execution vulnerability. Such security holes are not easy to find these days, so this has been the largest amount of money given by Facebook to a security researcher so far.
According to the researcher, it all started in September 2012 when he found an XML External Entity Expansion (XXE) bug in the Drupal component that handles OpenID. Since OpenID had been used by many services, Silva started performing tests to see which ones had been impacted.
Initially, he thought Facebook wasn’t vulnerable at all, until one day in November 2013 when he was testing the social media service’s “Forgot your password” functionality. He found that the XXE vulnerability he identified over a year before had been affecting facebook.com/openid/receiver.php.