Facebook hacking by injecting XML payload into Word Document
Ramadan has successfully found vulnerabilities in major service providers like Google, Facebook, Twitter, Microsoft etc. and has been rewarded with bug bounty reward by them. An XXE (XML External Entity ) is a method that exploits a weak XML parsing mechanism. you’re free to read more about these fixeshere. Facebook had clarified that it had fixed all of its servers so finding another XXE vulnerability seemed highly unlikely. Yet Ramadan decided to continue his quest....