I once (2009) found a similar bug that allowed leaking the ID and personal info of a FB user when their browser loaded a seemingly innocent tag (so it could be embedded in a forum post, for example). Sadly, it was before FB had a bug bounty program, so I didn't receive anything after I contacted them and they fixed the issue. I wrote about it here: http://blog.quaji.com/2009/07/facebook-personal-info-leak.ht...
Facebook exploit – Confirm website visitor identities
21–30 of 61 posts
Re: Facebook exploit – Confirm website visitor identities
#22Re: Facebook exploit – Confirm website visitor identities
#23I found an exploit like this in Google+ back in 2013 that worked in basically the same fashion (script tag and onload/onerror handlers) to identify users, and to tell if they were apart of certain groups. Google fixed the issue, but later wrote back: > The panel has determined your report did not meet the threshold for a reward or credit in our Hall of Fame. Thank you for reporting this issue and good luck with your…
How much did Google offer for a security bug (if they would have accepted it)?
http://www.tomanthony.co.uk/blog/google-xml-sitemap-auth-byp...
Re: Facebook exploit – Confirm website visitor identities
#24Is there something in here we're missing? Someone finds exploit, gets the bounty, facebook fixes and we have a timeline. Sounds like the system worked... are we looking for something else here?
I don't think there's much to see here...it is a cool bug though that doesn't require a super high level understanding of security to figure out. But a 6-9 month time to fix seems really long (also I would have thought a $1000 bug bounty is low for this type of exploit...but then again I'm not in this space too much to know the average rewards).
Not to say that’s the way it is at Facebook, just what I’ve seen in the past.
Re: Facebook exploit – Confirm website visitor identities
#25I found an exploit like this in Google+ back in 2013 that worked in basically the same fashion (script tag and onload/onerror handlers) to identify users, and to tell if they were apart of certain groups. Google fixed the issue, but later wrote back: > The panel has determined your report did not meet the threshold for a reward or credit in our Hall of Fame. Thank you for reporting this issue and good luck with your…
How much did Google offer for a security bug (if they would have accepted it)?
Looks like up to $30k per bug.
Re: Facebook exploit – Confirm website visitor identities
#26I found an exploit like this in Google+ back in 2013 that worked in basically the same fashion (script tag and onload/onerror handlers) to identify users, and to tell if they were apart of certain groups. Google fixed the issue, but later wrote back: > The panel has determined your report did not meet the threshold for a reward or credit in our Hall of Fame. Thank you for reporting this issue and good luck with your…
$1000 bounty for this seems really low.
Re: Facebook exploit – Confirm website visitor identities
#27Earlier quoted context omitted.
How much did Google offer for a security bug (if they would have accepted it)?
A bug by the same author (referenced in the article) that allowed anyone to undetectably upload a sitemap to any other person's website (and appear at the top of search results by claiming to be associated with the website) only got $5000, when it could have easily been sold for tens of thousands to blackhat SEO companies. So the answer is probably "way less than street value but still nonzero" http://www.tomanthony.…
Re: Facebook exploit – Confirm website visitor identities
#28I found an exploit like this in Google+ back in 2013 that worked in basically the same fashion (script tag and onload/onerror handlers) to identify users, and to tell if they were apart of certain groups. Google fixed the issue, but later wrote back: > The panel has determined your report did not meet the threshold for a reward or credit in our Hall of Fame. Thank you for reporting this issue and good luck with your…
This is better for researchers because they don't have to risk liability by weaponizing an exploit, and they also don't get lowballed by the companies who have arbitrary policies and arbitrary payouts that aren't compatible with responsible disclosure.
Re: Facebook exploit – Confirm website visitor identities
#29Earlier quoted context omitted.
$1000 bounty for this seems really low.
Why? There's no market for this bug. Nobody else will buy it. If you found an equivalent bug in, say, Grubhub, nobody would think it was worth much more than a token bounty. Is it just because Facebook is a big company and can afford to pay more for every bug, or is there a particular reason you think this bug is super valuable?
Re: Facebook exploit – Confirm website visitor identities
#30Earlier quoted context omitted.
$1000 bounty for this seems really low.
Why? There's no market for this bug. Nobody else will buy it. If you found an equivalent bug in, say, Grubhub, nobody would think it was worth much more than a token bounty. Is it just because Facebook is a big company and can afford to pay more for every bug, or is there a particular reason you think this bug is super valuable?
Wouldn't such orgs (or their vendors) pay at least $1k to find the people they want? I don't know what the right formula is to calculate bounty vs. expected black market value, but you only said nobody would buy it at all.