Live data from Hacker News

Instagram's Million Dollar Bug

exfiltrated.com

511–520 of 562 posts

Re: Instagram's Million Dollar Bug

#511
post #319

Earlier quoted context omitted.

Especially in the infrastructure department. This is the huge story here.. putting all your creds on S3 in the open protected by one key?? Craziness.

Yes, exactly this. Without escalating an RCE, how would he have been able to expose this absolutely huge flaw? The initial report was inconsequential, but this seems like at the very least a much more than $2500 bug. If things like this are considered "unethical" it kind of makes finding million dollar bugs in a bug bounty close to impossible.

I feel that privilege escalation/lateral movement is implicitly discluded from almost all bug bounty programs, most researchers know that.

It's a really grey area beyond an initial 'access bug', so it pays not to go there. Otherwise, where should Wes have stopped? keep proving more vulnerabilities until he's downloaded their code? or got private photos of Zuckerbergs kid? Just to show that it is indeed a serious bug?

Re: Instagram's Million Dollar Bug

#512

Earlier quoted context omitted.

>> Delete the keys or I have to tell legal what's happening. >> The researcher NEEDED TO HEAR THAT. I'm not in security, but from the outside looking in, how things worked out just doesn't smell right. If "the researcher NEEDED TO HEAR THAT" is the priority, then why waste time looking up who the guy works for and calling them instead? The simplest and most obvious way to tell the researcher is to tell him directly i…

My reading of tptacek's subtext is that Facebook wanted to show the researcher that they were really , ALL-CAPS serious, as in "get you fired and ruin-your-livelihood if you don't stop" serious. These mafia tactics are fine because the Facebook CSO "built a good team and knows what he is doing"

...which all adds up to a smell of "tptacek knows that team is good, because he's on it".

Re: Instagram's Million Dollar Bug

#513

Earlier quoted context omitted.

What possible motivation did Facebook have for contacting the company with whom this person had a contract employee relationship with, other than to implicitly threaten problems for both? There was no implication that he was doing this other than on his own, and he had cleared it with his employer. Presumably he didn't email Facebook with a corporate email account, and presumably his employer wasn't in a position whe…

> Presumably he didn't email Facebook with a corporate email account "At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes." From Alex Stamos's writeup: https://www.facebook.com/notes/al…

Wes has a footnote update:

> I never contacted Facebook or Alex using my work email account. It was only after Alex contacted my employer via email that I sent a reply from my work account. Alex indirectly contacted me at work, not the other way around.

Re: Instagram's Million Dollar Bug

#514

Earlier quoted context omitted.

No, Alex just assumed. Why didn't he just ask Wes if he was doing this for Synack?

He "assumed" because the researcher signed up for the Facebook bounty program as an employee of Synack and used his Synack email to communicate with Facebook. He wasn't guessing. He didn't look the guy up on LinkedIn.

> At this point, it was reasonable to believe that Wes was operating on behalf of Synack

> He "assumed" because the researcher signed up for the Facebook bounty program as an employee of Synack and used his Synack email to communicate with Facebook. He wasn't guessing. He didn't look the guy up on LinkedIn

This is a load of bolony / ass-covering by Alex - Facebook's bounty program explicitly deals with individuals only, not companies and Alex knows this. From https://www.facebook.com/whitehat/

> We only pay individuals

edit: down-voters, please point out the faults in my logic.

Re: Instagram's Million Dollar Bug

#516

Earlier quoted context omitted.

> All the experienced security guys itt... Ah, so those who disagree are inexperienced? No true scottsman indeed!

How is that a "no true scotsman"? Most people in this thread commenting have not indicated they work in the infosec industry. (For the record, I do, though I'm not sure I'd flatter myself by saying I'm "experienced" exactly.)

The problems I have with your absolute statement:

* You are stating that all (not some) experienced security folks are agreeing unanimously. The implication is that those show disagree are not "experienced security guys" (as you called them: "everyone else") - they are the ones who aren't true scotsman

* you assume those who don't explicitly indicate that they work in infosec industry do not work in the infosec industry

* also, you do you need to be "experienced" in the infosec industry to be correct / wrong.

Re: Instagram's Million Dollar Bug

#517
"As a researcher on the Facebook program, the expectation is that you report a vulnerability as soon as you find it. We discourage escalating or trying to escalate access as doing so might make your report ineligible for a bounty. Our team accesses the severity of the reported vulnerability and we typically pay based on its potential use rather than rely on what's been demonstrated by the researcher."

Well, FB feels your bug bounty is worth $200? Strike that figure. We feel like your bug bounty is worth a $100 advertising credit, if you buy $100 in advertising? Next time just report the bug. Thanks!

(I don't know if my innate dislike of FB, or I feel it shouldn't be up to a company to determine what they feel a bug is worth? If you are going to have a bug program--put in some Very solid rules? They shouldn't be just winging it at this point? It's not some cute little start up? It's a huge machine that's making a fortune off it's victim?

I'm still not sure if FB really cared about this hacker's escalation of a potential attack, or it's about money? Would I want a hacker to show me my vulnerability with my clients information--no, but make that crystal clear in the TOS.)

Re: Instagram's Million Dollar Bug

#518
post #92

Earlier quoted context omitted.

I don't know. I feel bad for Alex but if we want to suggest that Facebook's vulnerability disclosure policy was poorly written, I will ruefully agree. When you stand up a bug bounty program, you are giving strangers permission to do something that they would otherwise be prosecuted for doing. You should be extraordinarily careful when you do that, and your rules of engagement should be crystal clear. These weren't.

EDIT: Having read the CSO's explanation that the guy was using his company work email, it makes more sense why the CSO would contact the company (and explains away the pettiness my comment was referring to) One thing I notice: if the CSO felt like this person did something grossly illegal and irresponsible, why not go straight to the police? Why instead go to the man's employer and speak passively aggressively? Parad…

The researcher has already updated his post regarding the use of his company email. Apparently your original point still stands:

> I never contacted Facebook or Alex using my work email account. It was only after Alex contacted my employer via email that I sent a reply from my work account. Alex indirectly contacted me at work, not the other way around.

Also, why would he be doing this work at the behest of his employer when (IIRC) Facebook's bounty program only pays out to individuals? It would automatically make him ineligible to claim the bounty.

To me it seems like Alex Stamos tried to use some good old threaten-your-livelihood intimidation tactics and failed miserably.

Re: Instagram's Million Dollar Bug

#519

Earlier quoted context omitted.

No, Alex just assumed. Why didn't he just ask Wes if he was doing this for Synack?

He "assumed" because the researcher signed up for the Facebook bounty program as an employee of Synack and used his Synack email to communicate with Facebook. He wasn't guessing. He didn't look the guy up on LinkedIn.

From Wes' updated post:

> I never contacted Facebook or Alex using my work email account. It was only after Alex contacted my employer via email that I sent a reply from my work account. Alex indirectly contacted me at work, not the other way around.

Re: Instagram's Million Dollar Bug

#520
post #152
post #37

Earlier quoted context omitted.

To ensure that this person deleted the credentials they had taken from the server they popped with the RCE, obviously. Again: read the timeline. He submitted a finding with AWS creds taken from the server he popped on October 22 --- on December 1, more than a month after Facebook shut the server down . He took AWS creds from a Facebook server and saved them on his laptop for more than a month. WHY?

Surely a competent technology company would realize the using creds that were stored on a known-compromised server is bad and change them immediately, right?

Without having a position in this debate myself: I think that's not quite fair.

My understanding is this: They got a report that a server can be compromised and fixed that vulnerability. Unbeknownst the reporter grabbed a huge amount of (remote! not on that server, btw) data to play with.

Later the reporter returns to Facebook and says 'Btw, I got all these valuable pieces of information and have those for quite a while'.

Only at that point can you panic and rotate keys, but now you notice that a third party had access to all these keys for a month already. What else did they get? Maybe the researcher sat in a posh coffee place and grabbed interesting Instagram credentials (using the certificate) or escalated this further, gaining even more access based on the exposed information so far.

In my world, Facebook/Instagram are basically completely owned and have to assume that this guy grabbed ~everything~. They probably need to hire (vs. doing a bug bounty) people to grab the same data from the same buckets to look for potential follow-up targets that were _not_ disclosed, but might've fallen to the same bug hunter.

Who's to say that the guy doesn't come around on New Year's Eve with Yet Another Disclosure based on the same 'attack'?

I hate the 'contact the employer' part, but I'd hate to be in FB's shoes far more. I can hate the company and feel for its CSO/IT staff in this aftermath at the same time.

Post reply on HN