Security researcher is paid $12,500 by Facebook, after discovering major security flaw
Security researcher Arul Kumar was paid $12,500 by Facebook, after discovering and reporting a bug that would allow any user to delete the photos of other Facebook users, simply by changing parameters in a URL.
The severity of the security flaw apparently induced Facebook to pay Kumar far more than the base bounty of $500 for bugs reported through the website’s white hat security program.
The flaw resided in Facebook’s Support Dashboard. If Facebook refused to remove an image that an attacker claimed to find offensive, the attacker would be given the option of sending a request for deletion to the owner of the picture.