Subscribe / Unsubscribe Enewsletters | Login | Register

Pencil Banner

Facebook bug hunter stumbles on backdoor left by... another bug hunter

Lucian Constantin | April 25, 2016
The backdoor script stole Facebook employee credentials from a corporate server.

Still, Tsai was correct that someone else had been inside Facebook's network before him.

"There were two periods that the system was obviously operated by the hacker, one in the beginning of July and one in mid-September," he said.

The July incident happened to take place right around the same time that a remote code execution vulnerability in the Accellion File Transfer Appliance was publicly disclosed.

Tsai reported all of his findings to Facebook, which awarded him a $10,000 bug bounty and launched its own forensics investigation that was completed this month, prompting the researcher's blog post.


Previous Page  1  2 

Sign up for Computerworld eNewsletters.