Facebook Bug Bounties – Unofficial Treasure Map
facebook.com
Facebook Bug Bounties – Unofficial Treasure Map
1–10 of 22 posts
Re: Facebook Bug Bounties – Unofficial Treasure Map
#2But, I can't really say it's underpaid, as I have no idea what the black market for exploits is like, so maybe they are fairly paid.
Re: Facebook Bug Bounties – Unofficial Treasure Map
#3Re: Facebook Bug Bounties – Unofficial Treasure Map
#41) You could invite anyone to a Facebook event via their Facebook ID by simply doing an HTTP post of Facebook ID's to the event invitation script on this domain, but not on the main site. For some reason, on the mobile site they didn't implement the check to see if you were actually friends with the invitee. Since FB sends an email to each invitee, this was an enormous spamming loophole for quite a while.
2) For a long time, there was no frame-breaking script on m.facebook.com. You could clickjack essentially anything on Facebook this way. Years ago I did a proof-of-concept on this where I clickjacked a platform app authorization, which let me receive the name, email, and other profile info of any user that did nothing more than click the X button on an annoying overlay I put on the screen.
Re: Facebook Bug Bounties – Unofficial Treasure Map
#5Re: Facebook Bug Bounties – Unofficial Treasure Map
#6Nice. Although I'm still on the fence about bug bounties at their current price, as I can't help but see this as potentially manipulative, like hackathons where a company owns what you make, this guided hacking seems to be taking advantage of people's passions in order to underpay them for work. But, I can't really say it's underpaid, as I have no idea what the black market for exploits is like, so maybe they are fai…
To be fair, Facebook owns those vulnerabilities since they wrote the code :)
>in order to underpay them for work.
You already know the bounties you would receive, if you think they are not fair, just don't look for vulnerabilities.
Re: Facebook Bug Bounties – Unofficial Treasure Map
#7So I assume they won't give a bounty, if somebody finds a bug like the possibility of calling their testing tool trough a chat message?
Re: Facebook Bug Bounties – Unofficial Treasure Map
#8Nice. Although I'm still on the fence about bug bounties at their current price, as I can't help but see this as potentially manipulative, like hackathons where a company owns what you make, this guided hacking seems to be taking advantage of people's passions in order to underpay them for work. But, I can't really say it's underpaid, as I have no idea what the black market for exploits is like, so maybe they are fai…
>where a company owns what you make To be fair, Facebook owns those vulnerabilities since they wrote the code :) >in order to underpay them for work. You already know the bounties you would receive, if you think they are not fair, just don't look for vulnerabilities.
However, vulnerabilities are worthless. It's the exploit that has value, and you wrote the code for that.
Re: Facebook Bug Bounties – Unofficial Treasure Map
#9Nice. Although I'm still on the fence about bug bounties at their current price, as I can't help but see this as potentially manipulative, like hackathons where a company owns what you make, this guided hacking seems to be taking advantage of people's passions in order to underpay them for work. But, I can't really say it's underpaid, as I have no idea what the black market for exploits is like, so maybe they are fai…
There is no black market for isolated vulnerabilities in a single website.