In April, the Belgian sex hacker de Cukener , found a major vulnerability in the application for tests on the Facebook Nametests, which are used by tens of millions of people. According to him, the application gained access to personal data of users and stored them in such a way that "any third party could request them." To check his hypothesis, Cukener created a site that he was successfully able to get his personal data through Nametes (including, for example, photographs) - even after the application is removed.
Cukener claims that he was engaged in studying vulnerabilities after Facebook, against the backdrop of data from the data of millions of users, has launched a program for the search for unlawful use of data for a reward.
According to the hacker, he reported his find on Facebook on April 22. On the 30th he was answered that they were studying the information. In mid -May, he again wrote on Facebook - and a week later I received an answer that the investigation of the problem would take from three to six months.
On June 25, Cukener, in his own words, noticed that Nametests changed the data processing method, closing the vulnerability. The company itself told him that they did not know about cases of its use. The hacker wrote on Facebook about the elimination of vulnerability; He was answered that this happened thanks to his appeal, and agreed at his request to translate his reward (eight thousand dollars) of the organization Freedom of the Press Foundation.
Facebook confirmed TechCrunch that after the appeal of the program participant, a vulnerability was eliminated in the NAMETESTS application. The company refused to answer why it took so much time, but indicated that they received the first message from it not on the 22nd, but on April 27.