My Bug Reporting Experience on Facebook

Sajan Ghimire - #InkSec
PenTester Nepal
Published in
2 min readJul 10, 2024

Last year, I encountered an unexpected glitch on Facebook that led me on a unique adventure. Here’s a simple look at what happened and what I learned from it.

Issue is, While using Facebook’s messaging system, I found a stubborn problem. After I left a group chat called ‘MATLAB official group’ and tried to delete it from my archived messages, it mysteriously kept coming back. No matter how many times I tried to remove it, it reappeared every time I refreshed the page.

Determined to get this fixed, I reached out to Facebook’s security team through their whitehat support messaging system. I provided a detailed description of the issue, including a video to demonstrate the glitch, hoping it would help them understand and fix the issue faster.

The back-and-forth communication with Facebook’s security team was quite an experience. They initially seemed confused and requested more details such as the HTTP request that failed and my user ID. The discussions continued over a period, with several messages exchanged to clarify the situation.

On October 31, they acknowledged the bug but explained that it didn’t qualify for a monetary reward since it didn’t pose a threat to user privacy or security🥺. Although it was a bit disappointing, the real satisfaction came later when they finally fixed the issue.

This taught me a lot about the inner workings of tech companies when it comes to handling user-reported issues. It emphasized the importance of persistence and the impact we can have in improving platforms, even if the immediate rewards aren’t tangible.

For anyone else who stumbles upon a bug, remember that your contributions are valuable. It’s about making the platform better for everyone, not just about the rewards. Keep exploring and reporting — your actions really can make a difference!
#stay_secure🙂 #happyLearning #FacebookBugBounty #InkSec

--

--