Published On: 11 Jun 2019
After doing some testing in the file upload functionality of Facebook groups I noticed that my files tab stopped working correctly. I then went through my requests sent one by one in an attempt to reproduce the issue I stumbled across.
When uploading a file to a group, if you change the filename to a single period ".", the file tab would then completely crash and be unload-able
The impact of this is that the files section is no longer usable and to get it back the victim would have to remake his entire group thus losing all the current members and content.
Step
1
Browse to the victims group
Step
2
Attempt to upload a valid file and capture the request in Burp Suite
Step
3
Change the filename to "."