Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

81–90 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#81
post #58
post #24

Earlier quoted context omitted.

> I sent random requests using intruder with a CSRF token and random emails with a new password to this endpoint /savepassword So this endpoint simply allowed setting up a new password with a POST request for the specified email address and he was able to guess the email .. ¯\_(ツ)_/¯

That’s how I read it as well, almost too absurd to believe. SetPassword and the parameters to the function are just username and newPassword. I guess they assumed there was authentication happening before the request would even be served (pre-existing session).

A good example of how security by obscurity can fail. Just because there's no url to an endpoint exposed doesn't mean it shouldn't be hardened

Re: I Hacked into Facebook's Legal Department Admin Panel

#82

Earlier quoted context omitted.

It doesn't have to be "easily accessible" to be valuable. Corporate espionage exists, insider trading exists (and is more common than you might think), there's any number of parties who might pay for insider info (once properly laundered) about Facebook activities. Why would "the government of Iran" care about what Facebook is up to? Isn't FB banned in Iran?

You forget that intelligence and espionage goes both ways. Iran could use FB in some way to attack the US, just like Russia did, just as it could shield itself from FB.

Russia bought lousy ads and ran some pages like your average boring marketer, hardly an attack.

Re: I Hacked into Facebook's Legal Department Admin Panel

#83
post #74
post #66

Earlier quoted context omitted.

> I'd demand Facebook pay out $75,000 minimum Wouldn't demanding money be blackmailing? A story from one of my startups: A student reached out to us regarding a security vulnerability on the website, demanding money for it. He refused to say what it was or provide evidence at first, so we couldn't assess it. He said he'd disclose it to others if we didn't. I definitely felt blackmailed. I am not a lawyer but it felt…

Unless litigating students is something your startup is interested in, I’d recommend ignoring that line of thinking and just hiring a good pen tester for a few months.

It’s really hard to say what something is worth if you are only allowed to sell it to one buyer. No competition between buyers. The only leverage is releasing the info and screwing a lot of people.

(Also sucks that you can release it anyway. But you do want to source these vulnerabilities from the world at large.)

Yet another reason why open source and collaboration may be better than capitalism and competition. Many hands make light work, with enough eyes all bugs are shallow, and all that.

(To be fair, open source lacks security by obscurity so a project becomes secure after many years and developers join it.)

Re: I Hacked into Facebook's Legal Department Admin Panel

#85
post #66

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

> I'd demand Facebook pay out $75,000 minimum Wouldn't demanding money be blackmailing? A story from one of my startups: A student reached out to us regarding a security vulnerability on the website, demanding money for it. He refused to say what it was or provide evidence at first, so we couldn't assess it. He said he'd disclose it to others if we didn't. I definitely felt blackmailed. I am not a lawyer but it felt…

It’s that second part.

“I’m going to do x if you don’t y.”

He’s under no obligation to disclose. But the second part is coercion.

x itself might also constitute a crime.

Re: I Hacked into Facebook's Legal Department Admin Panel

#86
post #32

Earlier quoted context omitted.

Many of these guys are based in Third World countries, it's more complicated to go after them over petty stuff.

This has nothing to do with it. See sibling comments for the actual reason: Facebook and other companies typically allow this kind of security research, as long as the intent is not malicious and the researcher operates within some boundaries.

This has everything to do with it. It is much easier for pentesters to do their job when they don't have to walk on eggshells.

Any U.S. based pentester would always think twice before logging in a compromised system.

Re: I Hacked into Facebook's Legal Department Admin Panel

#89
post #33

Earlier quoted context omitted.

A "market" needs a bit more than "is worth something". What multiplier of the $7500 bounty would you want for the trouble of committing a crime? Who's the buyer (FB afaik doesn't buy a whole lot of publicly traded companies, so it probably needs to be someone who can get into the deals, and quickly)? How do you find them? How do you convince that buyer that your deal is worth the money and the hassle of committing a…

In other words, how much would Pepsi pay for the secret recipe to Coke?

Pepsi would report the person to Coca Cola instead of buying the recipe.

https://thehustle.co/coca-cola-stolen-recipe

> Months earlier, when Pepsi received the trio’s initial letter, they’d promptly forwarded it to Coca-Cola, and informed them they had a leaker. In turn, Coca-Cola had brought in the FBI to conduct an undercover investigation.

> On July 5, 2006, Williams, Dimson, and Duhaney were arrested on charges of wire fraud and unlawfully stealing and selling trade secrets.

Re: I Hacked into Facebook's Legal Department Admin Panel

#90
post #66

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

> I'd demand Facebook pay out $75,000 minimum Wouldn't demanding money be blackmailing? A story from one of my startups: A student reached out to us regarding a security vulnerability on the website, demanding money for it. He refused to say what it was or provide evidence at first, so we couldn't assess it. He said he'd disclose it to others if we didn't. I definitely felt blackmailed. I am not a lawyer but it felt…

I suppose the illegal part would be the student threatening to disclose the vulnerability to others if you didn't pay. That seems like crossing the line into blackmail and being an accomplice of whoever he discloses to. But the student wouldn't be legally obligated to inform you of a vulnerability, and it wouldn't make sense to if you weren't willing to pay. I can see the difficulty though, I guess you'd need to have his identity so you could legally pursue him if there was no vulnerability and he ran away with the money. Or maybe you could write up some sort of contract requiring an in-person demonstration...
Post reply on HN