Facebook exploit – Confirm website visitor identities
tomanthony.co.uk
Facebook exploit – Confirm website visitor identities
1–10 of 61 posts
Re: Facebook exploit – Confirm website visitor identities
#2That's like six figure lawsuits right there, for a bug like that.
Re: Facebook exploit – Confirm website visitor identities
#3Someone finds exploit, gets the bounty, facebook fixes and we have a timeline.
Sounds like the system worked... are we looking for something else here?
Re: Facebook exploit – Confirm website visitor identities
#4Is there something in here we're missing? Someone finds exploit, gets the bounty, facebook fixes and we have a timeline. Sounds like the system worked... are we looking for something else here?
But a 6-9 month time to fix seems really long (also I would have thought a $1000 bug bounty is low for this type of exploit...but then again I'm not in this space too much to know the average rewards).
Re: Facebook exploit – Confirm website visitor identities
#5Is there something in here we're missing? Someone finds exploit, gets the bounty, facebook fixes and we have a timeline. Sounds like the system worked... are we looking for something else here?
Re: Facebook exploit – Confirm website visitor identities
#6> The panel has determined your report did not meet the threshold for a reward or credit in our Hall of Fame. Thank you for reporting this issue and good luck with your continued bug hunting.
That always kind of rubbed me the wrong way. I found a similar bug in Facebook [1], though it used image size instead of the script tag. Like the OP, I was given $1000. It definitely made me feel a lot more favorable towards Facebook's security team.
[1] http://patorjk.com/blog/2013/03/01/facebook-user-identificat...
Re: Facebook exploit – Confirm website visitor identities
#7It's interesting that there wasn't any rate limiting on this API, it seems like?
Re: Facebook exploit – Confirm website visitor identities
#8Re: Facebook exploit – Confirm website visitor identities
#9Is there something in here we're missing? Someone finds exploit, gets the bounty, facebook fixes and we have a timeline. Sounds like the system worked... are we looking for something else here?
I don't think there's much to see here...it is a cool bug though that doesn't require a super high level understanding of security to figure out. But a 6-9 month time to fix seems really long (also I would have thought a $1000 bug bounty is low for this type of exploit...but then again I'm not in this space too much to know the average rewards).
Re: Facebook exploit – Confirm website visitor identities
#10Is there something in here we're missing? Someone finds exploit, gets the bounty, facebook fixes and we have a timeline. Sounds like the system worked... are we looking for something else here?
No. But some people, myself included, are interested in this sort of thing.
It's also interesting to see the timescales of the fix. Posts like this demonstrate that the system worked, albeit perhaps a bit slower than we'd like to imagine.
Whilst the reports of bug hunting apparently within the scope of the bug bounty resulting in a legal team responding with a false dichotomy between an NDA or prosecution are particularly juicy, it's also nice to hear about the cases where that isn't the outcome.