How I Found and Reported Facebook's 2013 Timeline Vulnerability

What the Bug Actually Was
In August 2013, I discovered a flaw in a Facebook mechanism (the composer.php component) that let a user post directly to another user's timeline — even someone who wasn't their friend and had privacy settings enabled that should have restricted their wall to friends only.
Why I Escalated to Zuckerberg's Wall
I didn't go straight to demonstrating this on Mark Zuckerberg's own page. I first reported it through Facebook's official White Hat bug bounty channel, and to prove the exploit without violating anyone's real privacy, I used it to post on the wall of Sarah Goodin — a Facebook employee and college friend of Zuckerberg's — rather than a stranger's account.
Facebook's security team replied that the link showed only an error and that this "is not a bug." I resubmitted the same report explaining that viewing the post required either being Goodin's friend or Facebook-level administrative access — and was told again it wasn't a bug.
With no other way to demonstrate the severity of the issue, I used the same exploit to post directly onto Zuckerberg's timeline: "First, sorry for breaking your privacy and post(ing) to your wall, I (have) no other choice to make after all the reports I sent to (the) Facebook team." That got a response from Facebook's security team within minutes.
Why Facebook Didn't Pay a Bounty
Facebook's White Hat program requires researchers to test using their own accounts rather than posting to real users' walls without consent, and its minimum bounty at the time was $500. Because I'd posted to Goodin's and Zuckerberg's real accounts to demonstrate the bug, Facebook ruled the disclosure ineligible for payment under those terms, even after confirming the vulnerability was real.
Facebook security engineer Matt Jones later acknowledged on Hacker News that the team receives hundreds of reports daily and that a language barrier — English isn't my first language — likely contributed to the initial reports being dismissed rather than properly investigated.
The Response from the Security Community
Security researcher Marc Maiffret organized a fundraiser after the story broke, which had raised more than $8,800 within a day of launching, as a way for the security community to compensate the work Facebook's bounty program didn't cover.
Why This Case Still Gets Referenced
This incident is still cited in discussions of responsible disclosure policy because it exposed a real tension: bug bounty programs need rules to prevent abuse, but rigid rules can also mean a legitimate, serious vulnerability report gets dismissed if it doesn't arrive in the expected format from the expected kind of reporter. It's part of why many bug bounty programs have since built in more flexibility for triaging reports that don't perfectly match their submission templates.
Found this article useful? Share it with your friends
For donation, contact or follow https://khalil-shreateh.com/links/