Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

151–160 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#151
post #42

Earlier quoted context omitted.

Totally agree with your perspective here. There's security research and there's bug prospecting. Both have streaks of narcissists and showboaters but the latter seems to be thick with them. (edit: to clarify b/c this can easily be interpreted otherwise, I'm not calling the writer of this article either of those. The headline is a bit of cheap clickbait but the article is a good walkthrough of their mindset)

> There's security research and there's bug prospecting. If the end result of your work isn't a whitepaper or something similar from which others can learn, then you can call your work "security research". Bug bounty programs are mainly targeted at bug prospectors. > Both have streaks of narcissists and showboaters but the latter seems to be thick with them. Thank god for that. Blog posts like the one this thread is…

Respectfully, I feel like you all are making up a taxonomy that feels right to you, but that is definitely not accepted by the vuln research field.

Further: this idea that "research" is something we have to valorize, and that you have to meet a public interest threshold to be worthy of it, is itself a standard to which the real world does not adhere. There are lots of different kinds of "research" out there; there are researchers who look for cures for cancer, and there are "researchers" who maintain stacks of index cards full of competitive market intelligence gleaned from press releases. The term "researcher" is about the kind of work you do, not the use to which it's put.

Maybe I'm just old and not keeping up with what the kids these days are saying, but I don't think "bug prospector" is a thing.

Re: I Hacked into Facebook's Legal Department Admin Panel

#152

Earlier quoted context omitted.

Which is essentially market driven blackmail as far as I can see. Once I meet my new neighbours (one of whom is a moral philosopher by trade) I might ask about how to assess if that's ok. Personally it feels somewhat ok to me, speaking as someone who's built industrial espionage for money.

>> Which is essentially market driven blackmail as far as I can see. Modern medicine can also be like blackmail. Nobody has to actually threaten you, but nature will kill you unless you pay whatever the price of treatment. That's why we need competition, and why pharma companies like monopolies.

That statement is so true it's terrifying.

Re: I Hacked into Facebook's Legal Department Admin Panel

#153
post #81
post #58

Earlier quoted context omitted.

That’s how I read it as well, almost too absurd to believe. SetPassword and the parameters to the function are just username and newPassword. I guess they assumed there was authentication happening before the request would even be served (pre-existing session).

A good example of how security by obscurity can fail. Just because there's no url to an endpoint exposed doesn't mean it shouldn't be hardened

I think they assumed it was already hardened by requiring authentication, but didn't do any testing (or were unaware of this endpoint being a thing in the software they use).

Re: I Hacked into Facebook's Legal Department Admin Panel

#154

Earlier quoted context omitted.

Someone attractive can have the charisma of a dead fish.

People will pay for that

I personally find that super attractive if they lack all skills and intelligence and their only redeemable feature is being hot. If I was the type to pay for OnlyFans, I would certain shell out for a girl like that.

Re: I Hacked into Facebook's Legal Department Admin Panel

#155
post #57
post #45

Earlier quoted context omitted.

well, I might. I finish college back in 2019 and my teacher who was my counselor, runs several projects trying to make SE and CS more attractive to girls. I guess she'll have a harder job to do now, knowing that a girl could rely on her beauty to makes thousands of dollars exposing herself to strangers. Damn it, I have a two year old niece, I guess me and my brother better think something fast, so when shes a teenage…

It was always thus. In fact, until the ‘60s, a girl had to rely on her beauty and personality to eat and survive , i.e. by marrying. I have a daughter and, while obviously I’d prefer she didn’t end up on onlyfans, I really don’t want to limit what she should do or what talent she should leverage to reach happiness and/or prosperity.

> I’d prefer she didn’t end up on onlyfans

You must hate women empowerment and be sexist. You must actively support such wishes to be politically correct.

Re: I Hacked into Facebook's Legal Department Admin Panel

#157

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

They're brilliant at finding this stuff, sure, but incompetent when it comes to business acumen and valuing their work. Usually. Those that have some semblance of the latter, have received in the six figures from singular bounties. I haven't yet read this, and to be fair, most bug reports identify low severity issues which obviously don't deserve a six figure payout.

Re: I Hacked into Facebook's Legal Department Admin Panel

#158
post #37

well, I wasn't gonna to comment about this subject, but here we go: I find this value ($7,500.00) kind of low for a discovery like this. The other day, someone shared a link to an app [1] that estimastes how much a only fan user makes. I got tell, it got to me. I was never money orientated and I don't plan to become; but seeing how much someone makes by being naked in front of a web cam vs a software engineer salary…

> some of the only fans users makes in a month what a plain SE would make in a year.

Sure, of course some software engineers make in a month far more than a plain onlyFans user would make in a year.

Re: I Hacked into Facebook's Legal Department Admin Panel

#159

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

You can sell it to others. Zerodium buys 0days for 10 times or more than the original bounties.

https://zerodium.com/program.html

Re: I Hacked into Facebook's Legal Department Admin Panel

#160

Earlier quoted context omitted.

>> Which is essentially market driven blackmail as far as I can see. Modern medicine can also be like blackmail. Nobody has to actually threaten you, but nature will kill you unless you pay whatever the price of treatment. That's why we need competition, and why pharma companies like monopolies.

Here in Australia the state funds most medical care. In this case the blackmail vector, if we use that interpretation is the taxation system.

Blackmail with a bit of overhead tossed in then. At least most hackers keep the costs down and pass the savings on to you!
Post reply on HN