Since 2011, Facebook has operated a bug bounty program in which external researchers help improve the security and privacy of Facebook products and systems by reporting potential security vulnerabilities to us. An unreproducable bug due to the load balancer, an unusual Open Redirect bug. From Copy&Paste XSS To Full Account Takeover! How I leveraged an interesting CSRF vulnerability to turn self XSS into a persistent attack? How I made my first $$$ from finding a bug in Facebook, How I upgraded my privileges to the administrator of Odnoklassniki's url shortener, Facebook Bug Bounty: Reading WhatsApp contacts list without unlocking the device, U.S. Department of Defense - Info Disclosure and SQLi Writeup, Removing profile pictures for any Facebook user, Add users to roles on Facebook pages without an invitation consent (revisited). The vulnerability was found by Pethuraj, he is a security researcher from INDIA, and shared the write-up with us.. Google has acknowledge him and rewarded with $3133.7. We hope the following write-up will help to new bug hunters I am an undergraduate Computer Engineering student from Nepal, and an administrator at the Ask Buddie community We hope the following write-up will help to new bug hunters I went to Avishek's place and we took a few photos from that message were forwarded to my friend asked me for the pictures This is going to be about a reflected XSS bug affecting Facebook mirror websites He had a good phone and we took a few photos from his phone which he sent me via messenger I needed to prove that I can run arbitrary commands, not single-word commands I dumped PII information of customers in an update query - a Star Wars RCE Adventure with business manager This write up is about how I was able to bypass 2FA in a private ecommerce