Live data from Hacker News

How I could have hacked any Facebook account

anandpraka.sh

61–70 of 168 posts

Re: How I could have hacked any Facebook account

#62
post #27
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

This has been discussed many, many times on HN before. This bug would not cause Facebook much damage; in fact, Facebook and Google tend to overpay rewards for bugs for the purposes of goodwill and recruiting. Let's examine the facts: 1. A Facebook vulnerability is dangerous to Facebook. A WordPress vulnerability is dangerous to a quarter of the internet. Facebook is not a high value target, relatively speaking. 2. A…

>Say they buy it for $20,000. Do you really think someone will derive $20,000 of profit from this before it's caught and patched by Facebook?

FB is publicly traded at very high volume. You can make very large bets on its movement without being noticed. A hack of 10 celebrity facebook pages could probably drop the stock 5% in one day. You'd probably be able to make at least 20 to 1 on your money using options. The right organization could clear millions.

Re: How I could have hacked any Facebook account

#63
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

I agree. This was basically unrestricted access to any Facebook account. What a MASSIVE flaw. And who knows if this was already exploited in the wild? $15k is nothing at all compared to the scale of this issue...

It's not really unrestricted. Given that this is forcing the password reset, you can't silently do it, right? So anyone exploiting it knows there's a limited number of uses before people notice that their passwords are being reset by not them.

Re: How I could have hacked any Facebook account

#64
post #7

Earlier quoted context omitted.

Seeing as it's a brute-force per-account attack, a more accurate title would have been "How I could have hacked any Facebook account". Hacking "all of Facebook" would have been prohibitively resource-intensive for the hacker, and would likely have been caught and shut down before any real damage to the platform was done.

The hacker could of worked with the black market. They could use a botnet to slowly hack a large percentage of FB potentially. Seeing as how they disabled rate-limiting on a pubic facing beta with user data, why assume they would notice brute forcing against beta?

The attack involves resetting the user's password, which would have made the original user unable to access their own account until they reset the password back. After several such incidents were reported, Facebook likely would have cottoned on.

Re: How I could have hacked any Facebook account

#65
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

I agree. This was basically unrestricted access to any Facebook account. What a MASSIVE flaw. And who knows if this was already exploited in the wild? $15k is nothing at all compared to the scale of this issue...

Doesn't Facebook alert the user if it detects suspicious account login activity from an unknown location or IP?

Re: How I could have hacked any Facebook account

#66
post #23

Earlier quoted context omitted.

During the fiasco that was the last white-hat hacker to report he'd hacked Facebook, I posted this: > Bug bounties are supposed to represent a high probability payoff of a lesser amount of money for finding a bug. This is in comparison to going the black hat sales root, where probability of sale might be lower, but the payoff might be higher. I can imagine one or two state actors who might pay top dollar to have keys…

In other words, if you wanted to game the odds, you'd start by offering it on the black market, then if there were no takers after X number of days, offer it to Facebook?

It is unlikely that there is any black market for this bug, or for the RCE that compromised Facebook's crypto secrets.

https://news.ycombinator.com/item?id=11249173

Re: How I could have hacked any Facebook account

#67
post #28

On the subject of rate limiting, what is the best way to apply it across all endpoints, APIs and resources, external and internal, with minimal effort? Usually, I see this implemented only as an afterthought, and only on endpoints deemed 'dangerous', waiting for a disaster like this to happen...

It's a defense in depth scenario but most webservers have modules for it, Apache certainly does as I've used it not sure about nginx still not used that in production.

Re: How I could have hacked any Facebook account

#68
post #27

Earlier quoted context omitted.

This has been discussed many, many times on HN before. This bug would not cause Facebook much damage; in fact, Facebook and Google tend to overpay rewards for bugs for the purposes of goodwill and recruiting. Let's examine the facts: 1. A Facebook vulnerability is dangerous to Facebook. A WordPress vulnerability is dangerous to a quarter of the internet. Facebook is not a high value target, relatively speaking. 2. A…

What are you talking about? Facebook is not a "high value target" and "this bug would not cause Facebook much damage"? For example, if you wanted to monetize it, I have to imagine TMZ (or someone even less scrupulous) would pay a lot of money for dumps of A-list celeb and athlete Facebook accounts. You don't think Facebook having "The Fappening Part 2" on their hands is worth more than $15k to prevent? Or having ever…

He's right, and you are indeed recapitulating a discussion that has happened a zillion times on HN before. At some point (maybe I haven't read far enough down on the thread), The Grugq will chime in and confirm it, just in case you were doubting it. This isn't specific to Facebook; it's a common misapprehension of how bugs are valued for all SaaS companies.

People don't pay top dollar for speculative bugs. I'm sure there's some horrible market somewhere for stolen celebrity photos, but it generates a pittance compared to the people who harvest and exploit popped desktop computers.

It's not enough to imagine some way you could profit from the bug, for the same reason that you can't make 100 million dollars simply by coming up with the idea for an interesting startup. A viable exploit is just one part of the technical and business work that goes into profiting from a vulnerability. All the work, together, has to add up to less than the value of the exploit.

Moreover: pretty much nobody is planning out elaborate criminal enterprises based on Facebook bugs, because every one of those bugs takes a different form, has a different likelihood of discovery, and has a different payoff.

Re: How I could have hacked any Facebook account

#69
post #43
post #35

Earlier quoted context omitted.

Your comment does not reflect how vulnerability sales work in the real world. In the real world, vulnerabilities are sold to blackhat groups who want to make a profit by attacking as many websites as possible. Generally, these websites will have valuable credit card or other information that can be stolen from a compromised server. Compromised user accounts (not even the server! just users!) on a single website do no…

>Compromised user accounts (not even the server! just users!) on a single website do not constitute a valuable target. That statement is just plain wrong. With over a billion Facebook users, surely some of them are high-value targets.

He's not wrong, you're just misunderstanding him. He's not saying there aren't "valuable" or "interesting" Facebook accounts. He's saying that there aren't enough Facebook accounts with immediate drop-in value to an existing and lucrative criminal enterprise to create a competitive market for Facebook bugs.

Re: How I could have hacked any Facebook account

#70
post #35

Earlier quoted context omitted.

Your comment does not reflect how vulnerability sales work in the real world. In the real world, vulnerabilities are sold to blackhat groups who want to make a profit by attacking as many websites as possible. Generally, these websites will have valuable credit card or other information that can be stolen from a compromised server. Compromised user accounts (not even the server! just users!) on a single website do no…

> Hollywood plot, nothing more. The first example that comes to mind, "an organised trade in confidential personal information" https://en.wikipedia.org/wiki/News_International_phone_hacki... Just because this isn't the typical mass vulnerability SQL injection or XSS attack on a major framework doesn't mean it's basically worthless ($15k or less). The amount of damage that could be done to Facebook's reputation is en…

The black market does not put a high price on damaging Facebook's reputation.
Post reply on HN