Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

141–150 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#141

I've seen several stories about how HackerOne doesn't pay out bug bounties when bugs are reported. I, for one, wouldn't submit bugs/PoC to them, and I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne.

i think you might want to take a breath, rethink that position and not let your anger cause you to do something stupid. if you disclose a vulnerability, the company HAS EVERY RIGHT to sue you. every security researcher _thinks_ that they are protected by some unwritten good Samaritan law, when in fact, you are hacking and that carries financial and criminal penalties. this is why these bug bounties and established wa…

Insane comment. As a customer of these companies, this attitude is borderline criminal and a big cause of the repeated data breaches. Why should I trust any company that sues security researchers for disclosure?

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#142
post #139

I have not used Paypal since I had to file a dispute over an item I bought on ebay via Paypal. As a response they snail-mailed me a bunch of screenshots of an internal web-app with a bunch of info for someone else, SSN, CC number, address, etc. Everything I would need to do something bad. I called them and they did not seem to care so I called the guy (I had his number of course) but he never answered or responded to…

What does CYA mean? Haven't seen this acronym before.

https://en.wikipedia.org/wiki/Cover_your_ass

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#143

Earlier quoted context omitted.

reading both, looks to me like this is pretty much 2fa. isn't 2fa defined as a "second factor" beyond user:pass? isn't that what this bypass is about?

There is genuine disagreement about whether email qualifies as a second factor. As it is often just protected by a username and password the argument is that it's the same "something you know" factor as a password, or just an obfuscation of the same factor. I will say, that if cybernews have done what they say that they've done, and PayPal are claiming that it's not a concern, then PayPal are clearly in the wrong, an…

it's not just email, its phone also.

i recently recently logged inco company paypal from out of country and paypal complained it wants to confirm account via email, fine i confirmed. and then it said it also needs to conform the via phone. ie a call.

so it is a form of 2fa.

can i also complain how is 2fa a pain if multiple persons use that account. you cannot enable it if they allow only one user per account. there are workarounds where there are mutiple 2fa methods and i use the app and other person sms.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#144

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

I've never liked these rent-seeking bugbounty platforms which are inserting themselves as middle-men and mediators, but then take away the real value that comes from building direct client relationships. it's ok for people who start out and only want to work on vulns and not bother with "sales" (building long term client relationships). severely limiting though in the long run! much better to spend time on pitching y…

We've had bug bounty programs in the past. The biggest time sink is filtering the bullshit. You need someone with not amateur levels of technical chops to do it (which is someone who will have less time to do other things).

I've been that person before as both the 'do it yourself' bug bounty program as well as the 'filtered by hacker one' approach and I'll take the latter every time.

Outsourcing to Hacker One helps cut down the bullshit is where their value add is (and to a lesser extent the reputation system, however if someone is reporting on Hacker One I'll give them the benefit of the doubt). Anything else on top of that is just upsell.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#145
post #9

I've seen several stories about how HackerOne doesn't pay out bug bounties when bugs are reported. I, for one, wouldn't submit bugs/PoC to them, and I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne.

> I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne. Sadly you can't feed your children from media drama. Maybe, in the long run, but it's more likely to get sued.

> Sadly you can't feed your children from media drama.

So it seems like the real answer in these cases is selling the exploit on the "dark web". I mean why not? The vendor doesn't seem to care about security anyway.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#146

Earlier quoted context omitted.

> I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong. Actually this makes a pretty good case for this regulation being a joke. They clearly aren’t up to the responsibility of being a payment processor and are leaning on the law to sustain their business rather…

It's not a regulation. It's a contractual obligation between the merchant and the PCI counsel (which is made up by VISA/Mastercard/the backing banks/etc). It was put in place to avoid regulation.

Then perhaps regulation is necessary if this is their level of scrutiny?

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#147
I've had plenty of problems with bug bounty platforms and have completely stopped doing them. But most/all of these "critical" reports aren't critical and some of the behavior of their "researchers" is unprofessional at best. There's maybe one legit report here, and that's #2.

#1 "In order to bypass PayPal’s 2FA, our researcher used the PayPal mobile app and a MITM proxy, like Charles proxy."

So you need to be MITM'd and have a malicious cert installed? Yeah... not "critical" and out-of-scope for most places.

For "#2 Phone verification without OTP", look at the messages they were sending. Did they not understand H1's responses? Repeatedly demanding answers isn't a great look. It's not surprising it was locked.

For #3: it requires stolen creds. A "security" flaw that requires stolen creds and brute forcing isn't going to get much traction anywhere.

#4 was a dupe

#5 is a self XSS, no one accepts these

#6 is a stored self XSS and a dupe

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#148

Earlier quoted context omitted.

They had out-of-scope issues closed as being out-of-scope, which automatically lowers their reputation on the platform. The researchers are outraged: > When we submitted this to HackerOne, they responded that this is an “out-of-scope” issue since it requires stolen PayPal accounts. As such, they closed the issue as Not Applicable, costing us 5 reputation points in the process. But Paypal's policy really couldn't be c…

Yet paypal's policy explictly says authentication bypasses, like the 2FA bypass they showed, are in scope >Authentication or authorization flaws, including insecure direct object references and authentication bypass Reading with the context of the other out-of-scope issues. I think they meant that the ability to buy or steal someones credentials is not a vulnerability in and of itself. >Vulnerabilities involving stol…

They apparently have fake / security theater 2FA, where things are as inconvenient as 2FA, but pay pal explicitly doesn’t care that it’s easily bypassed, and full of security bypasses.

They also have opt-in 2FA.

It’s unclear which one the author bypassed.

Perhaps the confusion is by design on paypal’s side? Presumably giving people a false sense of security helps them close disputes without paying out?

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#149
post #71

Earlier quoted context omitted.

no shit PCI-DSS is a farce it's just there to make people that don't know anything about technology feel better

It's certainly very effective at providing said people with a false sense of security. It's also another buzzword they can utilize to waste people's time during meetings.

It's just like ISO-9001.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#150

Earlier quoted context omitted.

Their full "out of scope" list also includes MITM attacks, which would exclude most of what's in this article. I guess my confusion now is why PayPal even purports to offer bug bounties if they're going to craft an "out of scope" list that allows them to reject every submitted report.

> I guess my confusion now is why PayPal even purports to offer bug bounties if they're going to craft an "out of scope" list that allows them to reject every submitted report. They're not; you're just choosing to assume bad things about them. Their out-of-scope list is fairly standard. If you asked a guy on the street "what would hacking PayPal look like?", the answer they imagined would probably be in scope. For ex…

I'll happily admit that I have no experience with bug bounty programs. I'm just a heavy PayPal user who's shocked to learn that PayPal apparently doesn't care whether someone is able to bypass their security measures. Whether or not that's "standard" doesn't really change my reaction.
Post reply on HN