Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

301–310 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#301

Earlier quoted context omitted.

You're right; that's what ATO means here.

Same difference. Anti account take over and account authentication, because similar methods would be deployed (i.e., multifactor authentication, heuristic, etc.)

No, obviously not.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#302

Earlier quoted context omitted.

My experience with PayPal, from dev support to account managers, has been an absolute shit show. They were simply the first to their market and it's hard to kick them out.

It was difficult at first, this happened quite some time ago, but these days it seems there are lots of non-paypal options.

Most turnkey ecommerce solutions (for my case, event ticketing services like Tito and Eventbrite) seem to mainly support only Stripe and PayPal.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#303

People have a weird mental model of how big-company bug bounty programs work. Paypal --- a big company for sure, with a large and talented application security team --- is not interested in stiffing researchers out of bounties. They have literally no incentive to do so. In fact: the people tasked with running the bounty probably have the opposite incentive: the program looks better when it is paying out bounties for…

> It should, I hope, go without saying that nobody is required to run a bounty in the first place, and most companies probably shouldn't.

Really? Most companies? That seems like an extraordinary claim.

I'm not a security researcher but if I stumbled on some security issue in something that's not open-source and not owned by my employer, the only way I'd consider reporting it is if they have a bug bounty / responsible disclosure program. Otherwise I'd expect it would be about as likely for me to receive a "thank you" as a knock on the door from law enforcement.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#304

Earlier quoted context omitted.

It presumes a definition of "responsible" that suits the interests of vendors and treats the safety of end-users as an externality, in such a way that anyone operating in good faith and responding to different legitimate incentives is by definition "not" disclosing "responsibly". It's a linguistic ploy, and not one that should be dignified. In 2020, non-ironic use of the term "responsible disclosure" has become somew…

That sort of makes sense, but what are examples of other legitimate incentives that might compel a researcher to disclose the presence of a vulnerability before the vendor has a fix?

Google Project Zero have been unequivocal about how their forced disclosures have caused vendors to release security patches earlier and more frequently[0], which is a win for everybody.

Otherwise, research suggests that the chances of a vulnerability being independently rediscovered within three months may be as high as 1 in 5 for certain types of defects[1]. This means that even if you don’t know a particular vulnerability is being actively exploited, you’ll eventually find one that’s being quietly exploited by someone. Since you don’t know which one it’ll be, early disclosure at least gives end users the opportunity to apply mitigations and hopefully burns a 0-day being used by an internet bad guy.

[0] https://googleprojectzero.blogspot.com/p/vulnerability-discl... - “Why are disclosure deadlines necessary?”

[1] https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2928758

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#305

Earlier quoted context omitted.

Help me out here, in what way is it Orwellian? I always assumed the responsible part had multiple non-conflicting meanings, that 1) The researcher would not disclose it to the public until the vendor has a reasonable amount of time to fix it and 2) the vendor is assumed to want to do the right and responsible thing in fixing the flaw.

It presumes a definition of "responsible" that suits the interests of vendors and treats the safety of end-users as an externality, in such a way that anyone operating in good faith and responding to different legitimate incentives is by definition "not" disclosing "responsibly". It's a linguistic ploy, and not one that should be dignified. In 2020, non-ironic use of the term "responsible disclosure" has become somew…

You’re right that I am a software engineer, not a vulnerability researcher. I keep up with vulnerability research only insofar that I need to be aware of new classes of exploit so that I can write secure code (and, hey, it can be interesting!).

So, what is the correct term that is supposed to be applied to the approach of disclosing to a vendor first, giving them a hard deadline, and then doing a public disclosure? As far as I know, it’s not “coordinated disclosure”, since “coordinated disclosure” normally means the vendor controls the timeline.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#306

HackerOne is complete garbage. I spent close to a month digging into Uber and compromised their m.uber.com mobile endpoint; they hemmed and hawed and then awarded the $25K to another HackerOne top performer stating that he had discovered the exact same vulnerability the day before I had submitted the report. What's weird about it is that I was using Burp Proxy for everything, and this guy was directly connected to Po…

Hi, I work at PortSwigger. > Uber was running some promotional for a free three month license for Burp Proxy This is flat out wrong - the promotional partnership was done with HackerOne. > What's weird about it is that I was using Burp Proxy for everything... Burp Suite is used by tens of thousands of security experts and if we posted vulnerability data back we would get caught in about ten seconds. Also it would be…

Either Uber lied about this guy discovering the flaw so they didn't have to pay me, or Burp Proxy is sending telemetry back to Portswigger with high value vulnerabilities being discovered with the platform. I worked with nobody on this attack, I shared no information with anyone else, and submitted a remote execution vulnerability using HackerOne's supposedly secure triage system.

I wrote it all up on Medium, it got close to 400K reads over the 2018 Christmas holiday with many other stories in a similar vein related to incompetence in their security group. HackerOne is worthless, a scam unless you are full time working for them on bug bounties and already connected with their top ranked researchers.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#307

Earlier quoted context omitted.

You put in way too much effort. Call your credit card company first. Your credit card company profits from vendor (PayPal) mistakes by charging fees, so they are always happy to help you.

calling the Card issuer is always my first stop. CS these days is abysmal at most companies.

Doing a chargeback tends to burn any future business with the company--a big deal when you have a long standing account with them.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#308

HackerOne is complete garbage. I spent close to a month digging into Uber and compromised their m.uber.com mobile endpoint; they hemmed and hawed and then awarded the $25K to another HackerOne top performer stating that he had discovered the exact same vulnerability the day before I had submitted the report. What's weird about it is that I was using Burp Proxy for everything, and this guy was directly connected to Po…

Hi, I work at PortSwigger. > Uber was running some promotional for a free three month license for Burp Proxy This is flat out wrong - the promotional partnership was done with HackerOne. > What's weird about it is that I was using Burp Proxy for everything... Burp Suite is used by tens of thousands of security experts and if we posted vulnerability data back we would get caught in about ten seconds. Also it would be…

The triage was escalated to Rob Fletcher and Uber's security liaison Lindsey Glovin. You're right, Portswigger was running a promo with HackerOne. After I submitted a couple of different vulnerabilities, they then locked all of my reports and gave the $23,000 bounty award to "shubs (notaffy)"

These were three critical vulnerabilities on the m.uber.com endpoint; I was able to bypass their WAF and XSS_Auditor protections followed by demonstrating reflected SSL'ized XSS under *.uber.com certificate and remote javascript execution capability.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#309

HackerOne is complete garbage. I spent close to a month digging into Uber and compromised their m.uber.com mobile endpoint; they hemmed and hawed and then awarded the $25K to another HackerOne top performer stating that he had discovered the exact same vulnerability the day before I had submitted the report. What's weird about it is that I was using Burp Proxy for everything, and this guy was directly connected to Po…

Hi, I work at PortSwigger. > Uber was running some promotional for a free three month license for Burp Proxy This is flat out wrong - the promotional partnership was done with HackerOne. > What's weird about it is that I was using Burp Proxy for everything... Burp Suite is used by tens of thousands of security experts and if we posted vulnerability data back we would get caught in about ten seconds. Also it would be…

Bah there are several closed source plugins for Burp Proxy that are binary only and which constantly relay telemetry data back to Portswigger. I stopped using it for this exact reason, due to Burp Proxy's constant communication back to Portswigger. And the only thing that would need to be relayed back to Portswigger would be high value vulnerabilities that have been discovered.

Which would be trivial to implement as a covert channel in Burp Proxy's update process or any one of another methods of obfuscating and tunneling that data back to Portswigger.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#310

HackerOne is complete garbage. I spent close to a month digging into Uber and compromised their m.uber.com mobile endpoint; they hemmed and hawed and then awarded the $25K to another HackerOne top performer stating that he had discovered the exact same vulnerability the day before I had submitted the report. What's weird about it is that I was using Burp Proxy for everything, and this guy was directly connected to Po…

What would you expect HackerOne to do in the situation you describe? You filed a duplicate report. All of the malfeasance you allege is coming from Portswigger.

No idea which one it was, or both. 23K isn't something to sneeze at though, and would be plenty of incentive for the folk at Portswigger to work with douchebags like whoever this shubby dude is in order to collect these bounties.

24K for one bounty... or sell $299 licenses to nerds.. hmm, which one is more profitable...

Post reply on HN