Earlier quoted context omitted.
There is no market for bugs like these.
Could you please elaborate?
I Hacked into Facebook's Legal Department Admin Panel
31–40 of 301 posts
Re: I Hacked into Facebook's Legal Department Admin Panel
#32I've always wondered, aren't these types of bug investigations illegal? Aren't the investigators concerned about criminal prosecution? Not being snarky; I'm asking sincerely.
Many of these guys are based in Third World countries, it's more complicated to go after them over petty stuff.
See sibling comments for the actual reason: Facebook and other companies typically allow this kind of security research, as long as the intent is not malicious and the researcher operates within some boundaries.
Re: I Hacked into Facebook's Legal Department Admin Panel
#33Earlier quoted context omitted.
There is no market for bugs like these.
Isn’t legal involved in most business moves? Getting a wind of those ahead of a public announcement surely must be worth something ;)
What multiplier of the $7500 bounty would you want for the trouble of committing a crime? Who's the buyer (FB afaik doesn't buy a whole lot of publicly traded companies, so it probably needs to be someone who can get into the deals, and quickly)? How do you find them? How do you convince that buyer that your deal is worth the money and the hassle of committing a crime? How do you trust the buyer? How do you handle it if the hole gets closed before the buyer can profit? How do you value the risk it gets closed before you got your deal? Does all that work out in a way that you really don't want to take the bounty?
People buying backdoor access into companies probably happens occasionally, but it's probably not the easy high-profit thing compared to bounties many people think, but rather on the level of selling account information by the dozen for a few bucks - and for something like that you'll burn them quickly.
Re: I Hacked into Facebook's Legal Department Admin Panel
#34Re: I Hacked into Facebook's Legal Department Admin Panel
#35First pentester I found with 12k followers on Instagram: https://www.instagram.com/al_shwele/ but 8 on GitHub: https://github.com/Alaa-abdulridha Instagram keeps surprising me...
Re: I Hacked into Facebook's Legal Department Admin Panel
#36First pentester I found with 12k followers on Instagram: https://www.instagram.com/al_shwele/ but 8 on GitHub: https://github.com/Alaa-abdulridha Instagram keeps surprising me...
Fun fact: Tunisia, a relatively small North African country, was awarded the second highest number of Facebook bounties this year[1].
[1]: https://about.fb.com/news/2020/11/bug-bounty-program-10th-an...
Re: I Hacked into Facebook's Legal Department Admin Panel
#37The other day, someone shared a link to an app [1] that estimastes how much a only fan user makes. I got tell, it got to me. I was never money orientated and I don't plan to become; but seeing how much someone makes by being naked in front of a web cam vs a software engineer salary is kinda sad.
some of the only fans users makes in a month what a plain SE would make in a year. besides the fact that there are some serious wrong thing with the world, I thought this kind of skill would be more rewarded. Giving the fact that you could exploit this vulnerability to make a lot more money (or am I mistaken?).
Re: I Hacked into Facebook's Legal Department Admin Panel
#38$7500? Why are these bug bounties so piddling? How much would an exploit like this be worth on the black market? What's the potential loss / liability on Facebook's side? Hundreds of thousands? Millions?
There is no easily accessible "black market" for a hack like this. As an average person what is your alternative really? Pick up the phone and call the government of Iran? It is far more convenient (and safer) to just take the guaranteed ~$10K and move on with your life.
Corporate espionage exists, insider trading exists (and is more common than you might think), there's any number of parties who might pay for insider info (once properly laundered) about Facebook activities.
Why would "the government of Iran" care about what Facebook is up to? Isn't FB banned in Iran?
Re: I Hacked into Facebook's Legal Department Admin Panel
#39well, I wasn't gonna to comment about this subject, but here we go: I find this value ($7,500.00) kind of low for a discovery like this. The other day, someone shared a link to an app [1] that estimastes how much a only fan user makes. I got tell, it got to me. I was never money orientated and I don't plan to become; but seeing how much someone makes by being naked in front of a web cam vs a software engineer salary…
I'm not sure why you feel the need to imply some else's work isn't valuable to make the point that this work should be more valuable.
Re: I Hacked into Facebook's Legal Department Admin Panel
#40Earlier quoted context omitted.
Isn’t legal involved in most business moves? Getting a wind of those ahead of a public announcement surely must be worth something ;)
A "market" needs a bit more than "is worth something". What multiplier of the $7500 bounty would you want for the trouble of committing a crime? Who's the buyer (FB afaik doesn't buy a whole lot of publicly traded companies, so it probably needs to be someone who can get into the deals, and quickly)? How do you find them? How do you convince that buyer that your deal is worth the money and the hassle of committing a…
There are markets for vulnerabilities that slot seamlessly into existing business processes. In other words, you can tend to find a buyer for a vulnerability that would replace another vulnerability already being used, that accomplishes pretty much exactly the same thing as that vulnerability. The more people run that business process, the more likely it is that there's a liquid market.
Lots of organizations have business processes that rely on browser RCEs. Generally, there aren't many organizations that have business process that rely on serverside vulnerabilities in line-of-business applications that have instantaneous half-lives, because once the patch is developed they're gone.