🛡️ Facebook Bug Bounty Writeups Collection ✍️

💖 A curated list of Facebook bug bounty writeups by various security researchers.🌙

You can contribute to this collection by submitting your own writeup or any others you know of, written in clear and concise English. Your contributions will help others learn from your experiences and improve the security of Facebook's platform.

Table of Contents

---------------------------------------------------------------------

Account Takeovers

---------------------------------------------------------------------

Remote Code Execution

---------------------------------------------------------------------

2FA Bypass

---------------------------------------------------------------------

XSS

---------------------------------------------------------------------

CSRF

---------------------------------------------------------------------

SSRF

---------------------------------------------------------------------

Logic

Race conditions

---------------------------------------------------------------------

Rate Limits

---------------------------------------------------------------------

Open Redirect ($500+)

---------------------------------------------------------------------

Clickjacking

---------------------------------------------------------------------

Insecure Direct Object Reference (IDOR)

---------------------------------------------------------------------

Privacy/Spam

---------------------------------------------------------------------

Page Roles

---------------------------------------------------------------------

Facebook Ads

---------------------------------------------------------------------

Facebook Groups

---------------------------------------------------------------------

Phone number

---------------------------------------------------------------------

Email address

---------------------------------------------------------------------

BIP address

Facebook Bug:Getting other user's IP address from a Image on Facebook

---------------------------------------------------------------------

Symlink Attack

---------------------------------------------------------------------

Accellion’s Secure File Transfer

How I hacked Facebook and found someone's backdoor script

---------------------------------------------------------------------

XXE

---------------------------------------------------------------------

LFI

---------------------------------------------------------------------

SQLI

---------------------------------------------------------------------

Jenkins

---------------------------------------------------------------------

API

---------------------------------------------------------------------

GraphQL

---------------------------------------------------------------------

FQL

---------------------------------------------------------------------

Login Nonces

OAuth (AKA Stealing Access Tokens)

---------------------------------------------------------------------

Instagram

---------------------------------------------------------------------

Signal

---------------------------------------------------------------------

Slingshot

---------------------------------------------------------------------

Messenger Android

---------------------------------------------------------------------

Moments

---------------------------------------------------------------------

Moves

---------------------------------------------------------------------

Whatsapp

---------------------------------------------------------------------

Workplace

---------------------------------------------------------------------

Whitehat Test Accounts

---------------------------------------------------------------------

Facebook Event

---------------------------------------------------------------------

Facebook Business Page

---------------------------------------------------------------------

DOS Attack

---------------------------------------------------------------------

Facebook/Instagram Mobile App

---------------------------------------------------------------------

Some of the extra resources that you may want to look at !!

---------------------------------------------------------------------

Thanks

Special Thanks to :-