Facebook bug catcher reveals hacker value of Zuckerberg wall post stunt
Updated: IT security community rallies to raise funds for unemployed Facebook security bug catcher.


The Palestinian information system specialist that publicly exposed a Facebook security flaw claims he could have made thousands of dollars by selling on information about it to hackers.
Khalil Shreateh, found a vulnerability that allows people to post to anyone else's timeline, irrespective of whether or not the poster and the recipient are friends.
He flagged the issue via Facebook's White Hat security programme, which promises $500 for each flaw found, but the social networking giant denied it was a genuine flaw.
Shreateh responded by stating, "Ok, that mean (sic) I have no choice other than to report this to mark (sic) himself on facebook" and then proceeded to write a post on Facebook founder Mark Zuckerberg's wall about it.
The post from Shreateh to Zuckerberg's Facebook timeline apologised for breaking the billionaire's privacy but said he had "no other choice ... after all the reports I sent to [the] Facebook team".
The message concluded: "I appreciate your time reading this and getting someone from your company team to contact me."
Shreateh claims his account was disabled within minutes of the post with the company initially telling him it had the right to disable any Facebook account without giving a reason.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Shortly afterwards, a member of the Facebook team said they had disabled his account as a precaution, and that his original submission to the White Hat security team contained insufficient technical information for it to act.
"We cannot respond to reports which do not contain enough detail to allow us to reproduce an issue. When you submit reports in the future, we ask you to please include enough detail to repeat your actions," Facebook is reported to have told him.
"We are unfortunately not able to pay you for this vulnerability because your actions violated our Terms of Service. We do hope, however, that you continue to work with us to find vulnerabilities in the site," it added.
Facebook has confirmed Shreateh's account of events and that the messages he received from the security team are genuine.
Shreateh has since spoken to CNN stating that he could have sold the exploit to blackhat hackers for thousands of dollars, but didn't because he was a "good guy".
"I could sell (information about the flaw) on the black (hat) hackers' websites and I could make more money than Facebook could pay me," he told CNN.
"I never asked [Facebook], 'I want $4,000 or $5,000'," said Shreateh, who has reportedly been unemployed for two years.
"I didn't deal with them like that ... . (But) I really needed that money."
Following the interview, Marc Maiffret, chief technology officer of cybersecurity firm BeyondTrust, set up a fundraising initiative for the Shreateh on GoFundMe to raise awareness of the plight of independent security researchers.
Maiffret set a goal of $10,000 (6,386) in donations and managed to raise $10,830 (6,916) within one day.
On the fundraising page, Maiffret said: "gofundme to transfer the funds to Khalil, whom I am now in contact with. I hope this has raised awareness of the importance of independent researchers.
"I equally hope it has reminded other researchers that while working with technology companies can sometimes be frustrating, we can never forget the greater goal; to help the internet community at large, just as that community has helped donate over ten thousand dollars to Khalil within a day."
- This article was originally published on 19 August 2013 and updated on 21 August to include information on Shreateh's interview with CNN and Maiffret's fundraising effort.

Jane McCallion is Managing Editor of ITPro and ChannelPro, specializing in data centers, enterprise IT infrastructure, and cybersecurity. Before becoming Managing Editor, she held the role of Deputy Editor and, prior to that, Features Editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, and business strategy.
Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.
-
Why keeping track of AI assistants can be a tricky business
Column Making the most of AI assistants means understanding what they can do – and what the workforce wants from them
By Stephen Pritchard
-
Nvidia braces for a $5.5 billion hit as tariffs reach the semiconductor industry
News The chipmaker says its H20 chips need a special license as its share price plummets
By Bobby Hellard
-
Latest Meta GDPR fine brings 12-month total to more than €1 billion
News Meta was issued with two hefty GDPR fines for “forcing” users to consent to data processing
By Ross Kelly
-
"Unacceptable" data scraping lands Meta a £228m data protection fine
News The much-awaited decision follows the scraping of half a billion users' data and received unanimous approval from EU regulators
By Rory Bathgate
-
Meta notifies around 1 million Facebook users of potential compromise through malicious apps
News The vast majority of apps targeting iOS users appeared to be genuine apps for managing business functions such as advertising and analytics
By Connor Jones
-
Facebook business accounts hijacked by infostealer malware campaign
News Threat actors are using LinkedIn phishing to seize business, ad accounts for financial gain
By Rory Bathgate
-
Meta begins encrypting Facebook URLs, nullifying tracking countermeasures
News The move has made URL stripping impossible but will improve analytics
By Rory Bathgate
-
Meta hit with €17 million fine over multiple GDPR breaches
News The social media giant set aside over €1 billion in November to help it cope with potential fines arising from data protection investigations
By Zach Marzouk
-
Meta says Apple's iOS privacy changes will cost it $10 billion in 2022
News The company's CFO suggests Google "faces a different set of restrictions" because it pays Apple to remain the default iOS search engine
By Bobby Hellard
-
Google, Facebook fined €210 million for making it difficult for users to reject cookies
News Data regulator CNIL gives companies three months to provide a system for refusing cookies that is as easy as single click consent
By Zach Marzouk