WOW WOW you say "abused"... strong language there. He was trying to show the bug to them. This guy looks like he never read the TOS in the first place so he wasn't going after abusing. He didn't communicate properly is the way I would put it.
Really? Just because FB's security team was dismissive of a real bug report due to a language barrier they could have overcome with the tiniest bit of due diligence?
Had he sold this exploit, he could've made upwards of $20k-100k. Especially this bug. It allows marketing firms to post to peoples walls without even knowing them. That's a huge vulnerability at the moment when everybodies clamoring for 'social marketing'
I'd suggest that exploits for Facebook wouldn't actually sell that well on the black market. There's only one install of Facebook in the world and it's controlled centrally so can be patched at any time. It's not like an exploit for Windows which can go unpatched for months if people don't install an update - those are worth money because there's a real use case. With a Facebook exploit you'd get a few hours of spamming at best before it's patched and all the crap you posted is deleted - that's probably not worth the money.