How This Indian Bug-Bounty Hunter Hacked 1.6 Billion Facebook Accounts In exchange for not misusing the exploit and directly reporting it to Facebook, Zuckerberg's team rewarded him 10.5 lac rupees!

By Rustam Singh

Opinions expressed by Entrepreneur contributors are their own.

You're reading Entrepreneur India, an international franchise of Entrepreneur Media.

NuOilSuwannar / Shutterstock

Bug Bounty Hunting – the profession of ethical or "White hat" hackers who intentionally hack into servers and companies websites with the hope to find an exploit are finally receiving the popularity they deserve. One such bounty Hunter famous bug bounty hunter is Bangalore based Anand Prakash who managed to track a bug on Facebook.com that gained him unfiltered complete access to every Facebook user, or almost 1 billion profiles. Fortunately for Mark Zuckerberg, instead of going rougue and exploiting the bug to cause havoc, steal private images, conversations, credit card details and harass/blackmail anyone, he immediately reported the bug to Facebook's bug reporting team. In exchange for his work, Facebook instantly rewarded him US$ 15,000 or more than 10 lac rupees!

The bug

The vulnerability was relatively easy to exploit but had a massive impact. Whenever a user forgets his password on Facebook, he has an option to reset the password by entering his phone number/ email address on https://www.facebook.com/login/identify?ctx=recover&lwv=110

Facebook then sends a 6 digit code on the user's phone number/email address which user has to enter in order to set a new password. To prevent brute force attacks (where a computer keeps trying every logical combination of numbers on the login page till eventually reaching the correct password), Facebook has limited 10-12 attempts per account before waiting. Exploiting this, Anand gained access to any account on Facebook.

The exploit

Brute force protection was valid only on the main homepage, facebook.com. However a alternate URL, beta.facebook.com and mbasic.beta.facebook.com did not have the same protection. Exploiting this, he brute forced his way to gain access to any account at all by resetting their password. The newly set password could be used to login any account.

Impact

Facebook reacted immediately and fixed the bug within few hours. Just one week later, Anand received the confirmation and in light of the extremely crucial exploit, decided to reward him the bounty.

Anand has previously exposed several bugs in popular websites, including hacking 62.5 million Zomato users as well as deleting any note from any user's account for which he was awarded 2500US$ and forced unstoppable spamming of Facebook.com/thanks posting on behalf of any of your friends. He was awarded 12,500 US$ for exploiting this bug.

Anand Prakash (Image source: http://www.anandpraka.sh)

As you can see ethical hacking is an extremely value able profession and businesses can gain a lot from voluntarily encouraging users to find out bugs before unethical hackers find the same bug. They can save millions in data loss apart from losing the trust of millions of users. Entrepreneurs, start-ups and businesses should be encouraged to reward generously to bug bounty hunters. Does your start-up have a bug reporting reward system? Let us know in the comments on our official Facebook page, Entrepreneur India

Rustam Singh

Sub-Editor- Entrepreneur.com

Tech reporter.

Contact me if you have a truly unique technology related startup looking for a review and coverage, especially a crowd-funded project looking to launch and coverage.

Women Entrepreneur®

The Visionary: Devita Saraf, Chairperson & CEO, Vu Group

There was a time when the narrative around women entrepreneurs focused on their struggles. However, when we decided to look for a cover face who captured sustenance over two decades, we found Devita Saraf. Women have gotten media attention that has highlighted the uphill battle to break the glass ceiling, but now is the time they prove to be long-term leaders who can sustain and grow a business over decades. Here is the Chairperson and CEO of Vu Group, who has continued to build her brand as a visionary, who thinks long term and is also a symbol of strength for her team.

Business Ideas

70 Small Business Ideas to Start in 2025

We put together a list of the best, most profitable small business ideas for entrepreneurs to pursue in 2025.

News and Trends

Why Is 2025 a Bright Year For MediaTek?

With an aim to solidify its presence in the India market, MediaTek has a plan of action for 2025

Business News

'No One Is Paying What They Used to': Job Hopping Isn't As Lucrative As It Used to Be, According to New Data

The data shows that switching jobs yields only slightly more salary growth than staying put.

News and Trends

Chai Kings Secures Series A Funding from AVT, Eyes Nationwide Growth

The fresh funding will be used to expand, enhance its supply chain, improve customer engagement, boost operational efficiency, and innovate its offerings to meet evolving tea preferences in India.

News and Trends

Go Zero Raises INR 30 Cr in Series A to Fuel Expansion and Innovation

The Series A round saw continued support from DSG Consumer Partners, Saama Capital, and V3 Ventures, with additional participation from Aman Gupta (Shark Tank India) and Namita Thapar.