So what part is opensource about this? The github page mentions the pro version so I'm not sure that this is entirely open. Would I, for example, be able to run the code on a non-linode box and have access to the full software?
You're setting a great precedent for people to not use your program and instead, leak out bugs for malicious purposes rather than conform to your dodgy call of ToS. Saying "this is not a bug" doesn't even ask for more information, it cuts off his entire report as FALSE even though you have now admitted the bug was indeed not the intended way for Facebook to operate (people should not be able to post on other people's walls).
You seriously need to pay this guy like you promised, especially since he went to all the trouble to report it to you. This is a real low move for a company against this guy who obviously isn't a first-language English speaker.
Even if he violated a very minor and insignificant point in your terms, he only did it after you flat-out rejected his report. If you want to encourage reports, you need to be reasonable. If I was this guy, I would be absolutely furious after putting so much work in, doing it the pussy-way and reporting it to the company rather than leaking/selling it for spammers to use, only to get blindsided and literally make it all for nothing.
Holy crap!! I cannot believe Facebook would be such scumbag dodgy fckers to not pay the guy. He reported it as he should have and then they call some bullsht about terms of service.
Note to anyone else who discovers a vulnerability: leak it and blackhat the hell out of it. Exploit users maliciously to the full extent of your power.
The fact they are withholding features and maintaining a commercial product make this less enticing.
I've also not been a fan of litespeed after hearing years ago that they don't allow porn sites to use their web server. ie. their owners take it upon themselves to try and prohibit porn on the internet.