Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

21–30 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#21
post #11
post #3

I've always wondered, aren't these types of bug investigations illegal? Aren't the investigators concerned about criminal prosecution? Not being snarky; I'm asking sincerely.

In general you are on shaky legal ground. However, some companies (including Facebook) have a bug bounty program that provides a prescribed safe harbor that you can operate within to discover vulnerabilities within their products or infrastructure in exchange for some kind of recognition or award. The terms of Facebooks bounty are here: https://www.facebook.com/whitehat Based on a cursory glance and the fact that thi…

Yes. Most competent tech companies permissibly allow “security research” like this.

If you are genuinely trying to find exploits in good faith, and are acting within the parameters spelled out in their bug bounty program, it’s all good. You also may get paid.

This blog entry sort of dramatized what happened for clicks. I actually think it’s unwise to characterize any exploit like this, because it adds a PR dimension consumer companies just don’t want or need.

It sort of creates a sense of adversarial relationship which isn’t really what FB is after.

But it sounds like a risky endeavor put this way and probably helps get retweets attention in the short term.

Re: I Hacked into Facebook's Legal Department Admin Panel

#23
post #14

Earlier quoted context omitted.

There is no market for bugs like these.

not even for nation states/APTs? Are you sure about that?

I can’t speak for Thomas- but generally you’d want to invest your money in a vuln that is rather static. Web applications with attack surfaces that are constantly changing are not a good fit for a sophisticated attack with potentially huge blowback.

Re: I Hacked into Facebook's Legal Department Admin Panel

#24
post #15

I find the paragraph where the author described the exploit hard to read. Basically, he triggered the "Password Reset" process and then guessed the reset token?

> I sent random requests using intruder with a CSRF token and random emails with a new password to this endpoint /savepassword

So this endpoint simply allowed setting up a new password with a POST request for the specified email address and he was able to guess the email .. ¯\_(ツ)_/¯

Re: I Hacked into Facebook's Legal Department Admin Panel

#25
post #14

$7500? Why are these bug bounties so piddling? How much would an exploit like this be worth on the black market? What's the potential loss / liability on Facebook's side? Hundreds of thousands? Millions?

There is no market for bugs like these.

Hedge funds that employ blackhat hackers to steal confidential information from a public company would buy it.

Re: I Hacked into Facebook's Legal Department Admin Panel

#26
post #20

$7500? Why are these bug bounties so piddling? How much would an exploit like this be worth on the black market? What's the potential loss / liability on Facebook's side? Hundreds of thousands? Millions?

There is no easily accessible "black market" for a hack like this. As an average person what is your alternative really? Pick up the phone and call the government of Iran? It is far more convenient (and safer) to just take the guaranteed ~$10K and move on with your life.

> Pick up the phone and call the government of Iran?

Would that work? Asking for a friend.

Re: I Hacked into Facebook's Legal Department Admin Panel

#27
post #18
post #14

Earlier quoted context omitted.

There is no market for bugs like these.

Could you please elaborate?

Sorry, I didn't write clearly. What I meant was, there is no market for RCEs in random Facebook backoffice sites.

Re: I Hacked into Facebook's Legal Department Admin Panel

#30
post #3

I've always wondered, aren't these types of bug investigations illegal? Aren't the investigators concerned about criminal prosecution? Not being snarky; I'm asking sincerely.

Would you rather someone find it and report it to you, or sell it on the dark web / exploit it?

Making this kind of research illegal only makes sure the end result is always the latter.

Post reply on HN