Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

31–40 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#31
post #18
post #14

Earlier quoted context omitted.

There is no market for bugs like these.

Could you please elaborate?

Where are you going to go to sell it? are you going to go find some tor hidden service with a forum that you can post your exploit on and hope that somebody will give you some bitcoins for it? You think that those are not under heavy surveillance already? The "black market" for this kind of thing is way overblown. And if you think you can just go sell it to some nation state, think again. That's an easy way to end up in a federal supermax.

Re: I Hacked into Facebook's Legal Department Admin Panel

#32
post #3

I've always wondered, aren't these types of bug investigations illegal? Aren't the investigators concerned about criminal prosecution? Not being snarky; I'm asking sincerely.

Many of these guys are based in Third World countries, it's more complicated to go after them over petty stuff.

This has nothing to do with it.

See sibling comments for the actual reason: Facebook and other companies typically allow this kind of security research, as long as the intent is not malicious and the researcher operates within some boundaries.

Re: I Hacked into Facebook's Legal Department Admin Panel

#33
post #19
post #14

Earlier quoted context omitted.

There is no market for bugs like these.

Isn’t legal involved in most business moves? Getting a wind of those ahead of a public announcement surely must be worth something ;)

A "market" needs a bit more than "is worth something".

What multiplier of the $7500 bounty would you want for the trouble of committing a crime? Who's the buyer (FB afaik doesn't buy a whole lot of publicly traded companies, so it probably needs to be someone who can get into the deals, and quickly)? How do you find them? How do you convince that buyer that your deal is worth the money and the hassle of committing a crime? How do you trust the buyer? How do you handle it if the hole gets closed before the buyer can profit? How do you value the risk it gets closed before you got your deal? Does all that work out in a way that you really don't want to take the bounty?

People buying backdoor access into companies probably happens occasionally, but it's probably not the easy high-profit thing compared to bounties many people think, but rather on the level of selling account information by the dozen for a few bucks - and for something like that you'll burn them quickly.

Re: I Hacked into Facebook's Legal Department Admin Panel

#35

First pentester I found with 12k followers on Instagram: https://www.instagram.com/al_shwele/ but 8 on GitHub: https://github.com/Alaa-abdulridha Instagram keeps surprising me...

The majority of the accounts following him have 0 posts, very low amount of followers and follow thousands of other people. They are most likely bought or collected via an online bot tool. Further quantitative evidence: His posts have a very low amount of likes and comments.

Re: I Hacked into Facebook's Legal Department Admin Panel

#36

First pentester I found with 12k followers on Instagram: https://www.instagram.com/al_shwele/ but 8 on GitHub: https://github.com/Alaa-abdulridha Instagram keeps surprising me...

Not sure about that account, but penetration testing is actually fairly popular in the Middle East. Cost of living is typically quite low, so decent researchers can make a living from bug bounties.

Fun fact: Tunisia, a relatively small North African country, was awarded the second highest number of Facebook bounties this year[1].

[1]: https://about.fb.com/news/2020/11/bug-bounty-program-10th-an...

Re: I Hacked into Facebook's Legal Department Admin Panel

#37
well, I wasn't gonna to comment about this subject, but here we go: I find this value ($7,500.00) kind of low for a discovery like this.

The other day, someone shared a link to an app [1] that estimastes how much a only fan user makes. I got tell, it got to me. I was never money orientated and I don't plan to become; but seeing how much someone makes by being naked in front of a web cam vs a software engineer salary is kinda sad.

some of the only fans users makes in a month what a plain SE would make in a year. besides the fact that there are some serious wrong thing with the world, I thought this kind of skill would be more rewarded. Giving the fact that you could exploit this vulnerability to make a lot more money (or am I mistaken?).

1 - https://news.ycombinator.com/item?id=25393191

Re: I Hacked into Facebook's Legal Department Admin Panel

#38
post #20

$7500? Why are these bug bounties so piddling? How much would an exploit like this be worth on the black market? What's the potential loss / liability on Facebook's side? Hundreds of thousands? Millions?

There is no easily accessible "black market" for a hack like this. As an average person what is your alternative really? Pick up the phone and call the government of Iran? It is far more convenient (and safer) to just take the guaranteed ~$10K and move on with your life.

It doesn't have to be "easily accessible" to be valuable.

Corporate espionage exists, insider trading exists (and is more common than you might think), there's any number of parties who might pay for insider info (once properly laundered) about Facebook activities.

Why would "the government of Iran" care about what Facebook is up to? Isn't FB banned in Iran?

Re: I Hacked into Facebook's Legal Department Admin Panel

#39
post #37

well, I wasn't gonna to comment about this subject, but here we go: I find this value ($7,500.00) kind of low for a discovery like this. The other day, someone shared a link to an app [1] that estimastes how much a only fan user makes. I got tell, it got to me. I was never money orientated and I don't plan to become; but seeing how much someone makes by being naked in front of a web cam vs a software engineer salary…

Describing that work as "being naked in front of a webcam" is like calling software development "typing at a computer". You can make any job sounds trivial and downplay its value by describing it in a way that removes the skill and effort involved.

I'm not sure why you feel the need to imply some else's work isn't valuable to make the point that this work should be more valuable.

Re: I Hacked into Facebook's Legal Department Admin Panel

#40
post #33
post #19

Earlier quoted context omitted.

Isn’t legal involved in most business moves? Getting a wind of those ahead of a public announcement surely must be worth something ;)

A "market" needs a bit more than "is worth something". What multiplier of the $7500 bounty would you want for the trouble of committing a crime? Who's the buyer (FB afaik doesn't buy a whole lot of publicly traded companies, so it probably needs to be someone who can get into the deals, and quickly)? How do you find them? How do you convince that buyer that your deal is worth the money and the hassle of committing a…

I believe a good way to think about the market for vulnerabilities is this:

There are markets for vulnerabilities that slot seamlessly into existing business processes. In other words, you can tend to find a buyer for a vulnerability that would replace another vulnerability already being used, that accomplishes pretty much exactly the same thing as that vulnerability. The more people run that business process, the more likely it is that there's a liquid market.

Lots of organizations have business processes that rely on browser RCEs. Generally, there aren't many organizations that have business process that rely on serverside vulnerabilities in line-of-business applications that have instantaneous half-lives, because once the patch is developed they're gone.

Post reply on HN