Back to directory
WRITEUP #3903

How I hacked Facebook: Part Two

SSRFAccount takeoverCookie manipulation
by@alaa0x2(Alaa Abdulridha)
Bounty
54,580
Program
Meta / Facebook
Published
Mar 18, 2021
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://infosecwriteups.com/how-i-hacked-facebook-part-two-ffab96d57b19
RELATED WRITEUPS
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover
Directory Traversal, SQL Injection and Server-Side Request Forgery
SQL InjectionPath traversal
Self-XSS to ATO via Site Features
XSSSelf-XSS
IIS welcome page to source code review to LFI!
SSRFLFI
CSRF Bypass Using Domain Confusion Leads To ATO
CSRFAccount takeover

Built with ❤️ by Shubham Rawat