RT @hanno
simple vulns are the best: turned out you can reset a facebook pw with a 6 digit code and that you could bruteforce on their beta instance which didn't have a rate limit https://medium.freecodecamp.org/responsible-disclosure-how-i-could-have-hacked-all-facebook-accounts-f47c0252ae4d
Conversation
Notices
-
Philipp-Harald Rack (jomo@mstdn.io)'s status on Monday, 26-Feb-2018 15:03:37 UTC Philipp-Harald Rack - rugk -> ⚠️ Follow me at https://social.wiuwiu.de/@rugk repeated this.