Khalil Shreateh specializes in cybersecurity, particularly as a "white hat" hacker. He focuses on identifying and reporting security vulnerabilities in software and online platforms, with notable expertise in web application security. His most prominent work includes discovering a critical flaw in Facebook's system in 2013. Additionally, he develops free social media tools and browser extensions, contributing to digital security and user accessibility.

Get Rid of Ads!


Subscribe now for only $3 a month and enjoy an ad-free experience.

Contact us at khalil@khalil-shreateh.com

As many of you know that Facebook patched one of my latest exploits where i was able to tag users in non removable posts, you can read about it in this article : http://shar.es/1oXPXy

It seems that Facebook failed patching the vulnerability, somehow they placed a wrong code where it coverted the menu line choice with another facebook page . 

When a friend tag you in a post, you can simply click the right top arrow to choose to untag, unfollow, hide all .. etc . 

Facebook patching mistake converted the "Hide all from .." menu line to be " Hide all from ‎Ahmed Spider احمد سبايدر‎", where "Ahmed Spider" is a facebook page. 

 

How to check !

Copy this demo link : http://shar.es/1oXPXy 
Create A new post , Type @ and tag one of your friends . 
Hit enter for a new line after the tagged user line, paste the above link and wait for facebook to preview your link . 

Now your friend will see " Hide all from ‎Ahmed Spider احمد سبايدر‎" as the above picture shows . 

Bug reported, should to be patched correctly soon . 

 

 
Social Media Share