Social network Facebook has awarded Russian Andrey Leonov for the vulnerabilities found in the site's security. "Flaw" in the Security granted the status of critical.
Andrew found out that Facebook is using a vulnerable version of ImageMagick service. This software package for image pre-processing prior to publication, which is used in many popular sites. Using a security breach, the attackers were on a remote server to perform any commands, "hidden" code in the image file.
Vulnerability discovered and eliminated in May 2016. However, in November, Andrew managed to bypass the security of Facebook. He immediately informed about the dangers of social networks administration, the problem persists after two days.
Andrej told about his discovery:
Found vulnerability allows to execute arbitrary code on the server (s) owned by Facebook. But we must understand that, in spite of the fact that in itself is the code executi
...
Read more »