Earlier quoted context omitted.
> I sent random requests using intruder with a CSRF token and random emails with a new password to this endpoint /savepassword So this endpoint simply allowed setting up a new password with a POST request for the specified email address and he was able to guess the email .. ¯\_(ツ)_/¯
That’s how I read it as well, almost too absurd to believe. SetPassword and the parameters to the function are just username and newPassword. I guess they assumed there was authentication happening before the request would even be served (pre-existing session).
I Hacked into Facebook's Legal Department Admin Panel
81–90 of 301 posts
Re: I Hacked into Facebook's Legal Department Admin Panel
#82Earlier quoted context omitted.
It doesn't have to be "easily accessible" to be valuable. Corporate espionage exists, insider trading exists (and is more common than you might think), there's any number of parties who might pay for insider info (once properly laundered) about Facebook activities. Why would "the government of Iran" care about what Facebook is up to? Isn't FB banned in Iran?
You forget that intelligence and espionage goes both ways. Iran could use FB in some way to attack the US, just like Russia did, just as it could shield itself from FB.
Re: I Hacked into Facebook's Legal Department Admin Panel
#83Earlier quoted context omitted.
> I'd demand Facebook pay out $75,000 minimum Wouldn't demanding money be blackmailing? A story from one of my startups: A student reached out to us regarding a security vulnerability on the website, demanding money for it. He refused to say what it was or provide evidence at first, so we couldn't assess it. He said he'd disclose it to others if we didn't. I definitely felt blackmailed. I am not a lawyer but it felt…
Unless litigating students is something your startup is interested in, I’d recommend ignoring that line of thinking and just hiring a good pen tester for a few months.
(Also sucks that you can release it anyway. But you do want to source these vulnerabilities from the world at large.)
Yet another reason why open source and collaboration may be better than capitalism and competition. Many hands make light work, with enough eyes all bugs are shallow, and all that.
(To be fair, open source lacks security by obscurity so a project becomes secure after many years and developers join it.)
Re: I Hacked into Facebook's Legal Department Admin Panel
#84The person who wrote it probably was working under the assumption that the calling user was logged in, but still....
Re: I Hacked into Facebook's Legal Department Admin Panel
#85You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
> I'd demand Facebook pay out $75,000 minimum Wouldn't demanding money be blackmailing? A story from one of my startups: A student reached out to us regarding a security vulnerability on the website, demanding money for it. He refused to say what it was or provide evidence at first, so we couldn't assess it. He said he'd disclose it to others if we didn't. I definitely felt blackmailed. I am not a lawyer but it felt…
“I’m going to do x if you don’t y.”
He’s under no obligation to disclose. But the second part is coercion.
x itself might also constitute a crime.
Re: I Hacked into Facebook's Legal Department Admin Panel
#86Earlier quoted context omitted.
Many of these guys are based in Third World countries, it's more complicated to go after them over petty stuff.
This has nothing to do with it. See sibling comments for the actual reason: Facebook and other companies typically allow this kind of security research, as long as the intent is not malicious and the researcher operates within some boundaries.
Any U.S. based pentester would always think twice before logging in a compromised system.
Re: I Hacked into Facebook's Legal Department Admin Panel
#87Re: I Hacked into Facebook's Legal Department Admin Panel
#88Re: I Hacked into Facebook's Legal Department Admin Panel
#89Earlier quoted context omitted.
A "market" needs a bit more than "is worth something". What multiplier of the $7500 bounty would you want for the trouble of committing a crime? Who's the buyer (FB afaik doesn't buy a whole lot of publicly traded companies, so it probably needs to be someone who can get into the deals, and quickly)? How do you find them? How do you convince that buyer that your deal is worth the money and the hassle of committing a…
In other words, how much would Pepsi pay for the secret recipe to Coke?
https://thehustle.co/coca-cola-stolen-recipe
> Months earlier, when Pepsi received the trio’s initial letter, they’d promptly forwarded it to Coca-Cola, and informed them they had a leaker. In turn, Coca-Cola had brought in the FBI to conduct an undercover investigation.
> On July 5, 2006, Williams, Dimson, and Duhaney were arrested on charges of wire fraud and unlawfully stealing and selling trade secrets.
Re: I Hacked into Facebook's Legal Department Admin Panel
#90You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
> I'd demand Facebook pay out $75,000 minimum Wouldn't demanding money be blackmailing? A story from one of my startups: A student reached out to us regarding a security vulnerability on the website, demanding money for it. He refused to say what it was or provide evidence at first, so we couldn't assess it. He said he'd disclose it to others if we didn't. I definitely felt blackmailed. I am not a lawyer but it felt…