Skip to content

Penetration Testing Tools

  • Home
  • Google
    • Android
  • Information Security
    • Cyber Security
    • Cybercriminals
    • Data Leak
    • Malware
    • Vulnerability
  • Linux
  • Microsoft
    • Windows
  • Open Source Tool
  • Technology
  • Home
  • Google
    • Android
  • Information Security
    • Cyber Security
    • Cybercriminals
    • Data Leak
    • Malware
    • Vulnerability
  • Linux
  • Microsoft
    • Windows
  • Open Source Tool
  • Technology

Penetration Testing Tools

  • Vulnerability

Researcher Details 0-Click Facebook Account Takeover Vulnerability

by ddos · March 6, 2024

Nepalese cybersecurity researcher Samip Aryal made history by identifying a vulnerability in Facebook’s password reset system that allowed a malefactor to seize any account without any action from the victim.

Aryal’s discovery not only earned him an unprecedented reward from the company but also secured him a top position in Facebook’s Hall of Fame among white-hat hackers for the year 2024. The amount of the reward, however, remains undisclosed.

Aryal revealed that Facebook’s password reset feature lacked a limit on the number of attempts to request a code, enabling attacks without user intervention. An attacker could initiate a password reset request and brute-force the six-digit security code.

Aryal’s investigation demonstrated that when resetting passwords through Android Studio, users were prompted to receive a security code via a Facebook notification. Remarkably, the code remained valid for two hours, even after multiple unsuccessful entry attempts. Aryal noted that, unlike SMS-based resets, the code was not invalidated after several erroneous attempts.

By employing brute-force methods, Aryal managed to test all possible code combinations within an hour, uncovering a vulnerability that allowed the code to be displayed directly in the notification without needing to click on it. Aryal reported the flaw to Facebook on January 30, 2024, and by February 2, the issue had been resolved.

Share

Tags: 0-Click Facebook Account TakeoverFacebook Account Takeover

Follow:

  • Next story ChatGPT Users Hacked: Credentials Sold on Dark Web
  • Previous story CVE-2024-27198 and CVE-2024-27199: Critical Security Flaws Affecting TeamCity On-Premises

Search

MAKE THE WEBSITE ONLINE

  • Popular Posts
  • Tags
  • Technology

    How to Control Smart Devices on PC using Smart Life App

    July 19, 2025

  • AI Reverse Engineering

    Open Source Tool

    GhidraMCP: Revolutionizing Reverse Engineering by Connecting Ghidra to LLMs

    June 20, 2025

  • XSS C2, Browser Proxy

    Open Source Tool

    peeko: Browser-based XSS C2 for stealthy internal network exploration via infected browser

    June 21, 2025

  • WiFi Exploitation

    Open Source Tool

    WEF: Wi-Fi Exploitation Framework

    June 21, 2025

  • Open Source Tool

    Fofa Viewer: simple FOFA (cyberspace search engine) client

    June 23, 2025

  • AI Amazon AMD Android Apple ARM Artificial intelligence Asus ChatGPT chrome cyberattack cybersecurity facebook Firefox Github google Google Chrome Huawei India Intel Lenovo LG Linux Linux Kernel malware MediaTek Meta Microsoft microsoft edge Nvidia OpenAI open source Qualcomm ransomware Samsung SK Hynix Sony TSMC vulnerability windows Windows 7 Windows 10 Windows 10X Windows 11 Xbox




Reward

Brilliantly

SAFE!

meterpreter.org

Content & Links

Verified by Sur.ly

2022

  • Home
  • About Us
  • Contact Us
  • DMCA NOTICE
  • Privacy Policy

Penetration Testing Tools © 2025. All Rights Reserved.