Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

51–60 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#51
post #37

well, I wasn't gonna to comment about this subject, but here we go: I find this value ($7,500.00) kind of low for a discovery like this. The other day, someone shared a link to an app [1] that estimastes how much a only fan user makes. I got tell, it got to me. I was never money orientated and I don't plan to become; but seeing how much someone makes by being naked in front of a web cam vs a software engineer salary…

And software engineers make way more money than most healthcare workers... "There's something seriously wrong with the world"...

Main reason this is so is because of scale. One healthcare worker can look after a ward at most, one software engineer can write software that affects millions in a very small way, and some onlyfans accounts hit a smaller scale but with more revenue per user on average.

Re: I Hacked into Facebook's Legal Department Admin Panel

#52
post #26
post #20

Earlier quoted context omitted.

There is no easily accessible "black market" for a hack like this. As an average person what is your alternative really? Pick up the phone and call the government of Iran? It is far more convenient (and safer) to just take the guaranteed ~$10K and move on with your life.

> Pick up the phone and call the government of Iran? Would that work? Asking for a friend.

Even if it did, you wouldn’t want to do it. Someone like that can dispatch goons after the deal, to make sure they’ll be the only ones to know the hole.

Re: I Hacked into Facebook's Legal Department Admin Panel

#53
post #9
post #5

Interesting, but missing words and strange/missing punctuation make this a bit hard to read.

I suspect this is an ESL post.

It read more like an ADHD post (no offense), the author clearly had no time to waste on full stops.

Re: I Hacked into Facebook's Legal Department Admin Panel

#54
post #37

well, I wasn't gonna to comment about this subject, but here we go: I find this value ($7,500.00) kind of low for a discovery like this. The other day, someone shared a link to an app [1] that estimastes how much a only fan user makes. I got tell, it got to me. I was never money orientated and I don't plan to become; but seeing how much someone makes by being naked in front of a web cam vs a software engineer salary…

And software engineers make way more money than most healthcare workers... "There's something seriously wrong with the world"... Main reason this is so is because of scale. One healthcare worker can look after a ward at most, one software engineer can write software that affects millions in a very small way, and some onlyfans accounts hit a smaller scale but with more revenue per user on average.

The same argument I made for SE could be easily done for health workers. They are very important.

but I'll say this: I saw everywhere how underrated health workers are, and I agree. They should be paid a lot more; even more than athletes, in my book.

but how about SE and CS, have you heard anything? the whole economy would crumble, if weren't for online business. internet, apps, video chats, smart phones... I'm yet to see an AD saying thank you for what those brilliant CS and SE people have done for the world.

Re: I Hacked into Facebook's Legal Department Admin Panel

#55
post #20

$7500? Why are these bug bounties so piddling? How much would an exploit like this be worth on the black market? What's the potential loss / liability on Facebook's side? Hundreds of thousands? Millions?

There is no easily accessible "black market" for a hack like this. As an average person what is your alternative really? Pick up the phone and call the government of Iran? It is far more convenient (and safer) to just take the guaranteed ~$10K and move on with your life.

~10k and a minor hit of publicity. If you’re a security researcher I imagine that this is a solid boost to your reputation.

Re: I Hacked into Facebook's Legal Department Admin Panel

#56

First pentester I found with 12k followers on Instagram: https://www.instagram.com/al_shwele/ but 8 on GitHub: https://github.com/Alaa-abdulridha Instagram keeps surprising me...

The majority of the accounts following him have 0 posts, very low amount of followers and follow thousands of other people. They are most likely bought or collected via an online bot tool. Further quantitative evidence: His posts have a very low amount of likes and comments.

> The majority of the accounts following him have 0 posts, very low amount of followers and follow thousands of other people.

There's also the issue of "follower farmers". Basically, some spam accounts start following tens of thousands of people hoping at least some will check their profiles, maybe follow them back or click on their spam.

I noticed this mostly on Twitter, and after some digging, it turns out to be a common tactic used by spammer bots (or umm, "marketting teams"). I don't know how common that issue is on Instagram though but it could be same.

Re: I Hacked into Facebook's Legal Department Admin Panel

#57
post #45

Earlier quoted context omitted.

>but seeing how much someone makes by being naked in front of a web cam vs a software engineer salary is kinda sad. >some of the only fans users makes in a month what a plain SE would make in a year I'm sure if you could think of a way to make software engineers as appealing as naked women, you'd probably find yourself a pretty great job paying well over the people on onlyfans.

well, I might. I finish college back in 2019 and my teacher who was my counselor, runs several projects trying to make SE and CS more attractive to girls. I guess she'll have a harder job to do now, knowing that a girl could rely on her beauty to makes thousands of dollars exposing herself to strangers. Damn it, I have a two year old niece, I guess me and my brother better think something fast, so when shes a teenage…

It was always thus. In fact, until the ‘60s, a girl had to rely on her beauty and personality to eat and survive, i.e. by marrying.

I have a daughter and, while obviously I’d prefer she didn’t end up on onlyfans, I really don’t want to limit what she should do or what talent she should leverage to reach happiness and/or prosperity.

Re: I Hacked into Facebook's Legal Department Admin Panel

#58
post #24
post #15

I find the paragraph where the author described the exploit hard to read. Basically, he triggered the "Password Reset" process and then guessed the reset token?

> I sent random requests using intruder with a CSRF token and random emails with a new password to this endpoint /savepassword So this endpoint simply allowed setting up a new password with a POST request for the specified email address and he was able to guess the email .. ¯\_(ツ)_/¯

That’s how I read it as well, almost too absurd to believe.

SetPassword and the parameters to the function are just username and newPassword.

I guess they assumed there was authentication happening before the request would even be served (pre-existing session).

Re: I Hacked into Facebook's Legal Department Admin Panel

#59

First pentester I found with 12k followers on Instagram: https://www.instagram.com/al_shwele/ but 8 on GitHub: https://github.com/Alaa-abdulridha Instagram keeps surprising me...

The majority of the accounts following him have 0 posts, very low amount of followers and follow thousands of other people. They are most likely bought or collected via an online bot tool. Further quantitative evidence: His posts have a very low amount of likes and comments.

[deleted]

Re: I Hacked into Facebook's Legal Department Admin Panel

#60
post #42
post #21

Earlier quoted context omitted.

Yes. Most competent tech companies permissibly allow “security research” like this. If you are genuinely trying to find exploits in good faith, and are acting within the parameters spelled out in their bug bounty program, it’s all good. You also may get paid. This blog entry sort of dramatized what happened for clicks. I actually think it’s unwise to characterize any exploit like this, because it adds a PR dimension…

Totally agree with your perspective here. There's security research and there's bug prospecting. Both have streaks of narcissists and showboaters but the latter seems to be thick with them. (edit: to clarify b/c this can easily be interpreted otherwise, I'm not calling the writer of this article either of those. The headline is a bit of cheap clickbait but the article is a good walkthrough of their mindset)

> There's security research and there's bug prospecting.

If the end result of your work isn't a whitepaper or something similar from which others can learn, then you can call your work "security research".

Bug bounty programs are mainly targeted at bug prospectors.

> Both have streaks of narcissists and showboaters but the latter seems to be thick with them.

Thank god for that. Blog posts like the one this thread is about are really valuable to those of us interested in the work of others.

Post reply on HN