Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

171–180 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#171
post #66

Earlier quoted context omitted.

> I'd demand Facebook pay out $75,000 minimum Wouldn't demanding money be blackmailing? A story from one of my startups: A student reached out to us regarding a security vulnerability on the website, demanding money for it. He refused to say what it was or provide evidence at first, so we couldn't assess it. He said he'd disclose it to others if we didn't. I definitely felt blackmailed. I am not a lawyer but it felt…

Rather than the exploiter setting an arbitrary price (which would be closer to blackmail), I think parent comment was saying that the fair market value of disclosing such a bug was worth closer to $75k given the unique skill set required. Skilled engineers turn to cybercrime when white-hat bounties are insufficiently rewarding, so it is in everyone's interest to pay competitive rates for finding security vulnerabilit…

The fair market price of an entire app pentest of that legal dashboard application, one which would almost certainly find that bug† if run by a competent, reputable firm, along with many other bugs, run by consultants with bios and concluded with a deliverable that Facebook can file away, is probably somewhere between $20,000 and $35,000, so the idea that the fair market value of a single finding of that engagement is $75,000 is pretty hard to take seriously.

From my perspective, people weird ideas (in both directions!) about how much this stuff costs.

It's a little tricky to say because the blog post is cagey about what the vulnerability actually is, but I'm thinking about all of the password-reset-flow bugs I've ever seen that fit the rest of the pattern of the post and I'm pretty sure this is low-hanging fruit for a serious app pentest.

Re: I Hacked into Facebook's Legal Department Admin Panel

#172
post #128

Earlier quoted context omitted.

The majority of the accounts following him have 0 posts, very low amount of followers and follow thousands of other people. They are most likely bought or collected via an online bot tool. Further quantitative evidence: His posts have a very low amount of likes and comments.

I see this often on twitter. Some account with dozens of thousands of followers, if not more, and very little reaction to their tweet (less than 10 per tweet). It’s obvious to the trained eyes that they just bought followers. I can’t be mad honestly, it’s pretty cheap to signal that you’re a big deal by doing this.

That's often the case, but on Twitter it's sometimes also just inactive followers. Not uncommon to have 10+ year old accounts now which might've been big some time, but with 95% of those followers being inactive now.

Too bad Twitter didn't do the purge of inactive accounts, would've been interesting.

Re: I Hacked into Facebook's Legal Department Admin Panel

#173

Earlier quoted context omitted.

> There's security research and there's bug prospecting. If the end result of your work isn't a whitepaper or something similar from which others can learn, then you can call your work "security research". Bug bounty programs are mainly targeted at bug prospectors. > Both have streaks of narcissists and showboaters but the latter seems to be thick with them. Thank god for that. Blog posts like the one this thread is…

Respectfully, I feel like you all are making up a taxonomy that feels right to you, but that is definitely not accepted by the vuln research field. Further: this idea that "research" is something we have to valorize, and that you have to meet a public interest threshold to be worthy of it, is itself a standard to which the real world does not adhere. There are lots of different kinds of "research" out there; there ar…

The academic difference is quite distinct and is well understood in the research community there. Impressive vulnerabilities that could take down all of Google wouldn’t be accepted into any security research conferences/journals if the bug didn’t involve a new class of vulnerability or discovery method.

The term “bug prospector” might not be widely accepted, but people just looking for well understood bugs in production systems aren’t doing “research” in the academic sense anymore than a person at McDonald’s “researching” the menu to decide what to eat.

Re: I Hacked into Facebook's Legal Department Admin Panel

#174
post #88

Earlier quoted context omitted.

Dirbuster, gobuster, or some variant is probably what was used here.

Brute forcing is not fuzzing, neither of those are fuzzing tools

Yeah that's what I thought. Fuzzing doesn't discover API endpoints

Re: I Hacked into Facebook's Legal Department Admin Panel

#175

Earlier quoted context omitted.

I don't think so. Those people get paid whether or not you focus their attention on a perimeter-exposed RCE bug. By tipping them off, all you've done is make them more effective for a time. The bug is there whether a bounty hunter finds it or not. The other "leverage" you have, if you don't like $7K bounties for auth bypass on random backend thingies, is just not do hunt for bounties at all. Facebook knows that; thei…

As a company, why would I want to pay the hourly rate at all? Why not contract with a reputable bounty hunter, give them the level of access I'd give the hourly consultant, and pay the hunter bounties for what they find? Seems like that captures the "higher bugs per hour" advantage of the consultant while retaining the "you only get paid for directly producing value" advantage of bounties.

[deleted]

Re: I Hacked into Facebook's Legal Department Admin Panel

#176

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

I’d suggest anybody planning on making demands during a bug disclosure get some advice from a lawyer first. If you use the wrong phrasing, it’s very easy to end up committing extortion or blackmail.

I had some young college students report a very clever bug to me a few years ago, and they chose to take a rather aggressive approach when it came to discussing the bounty. We paid them a sum they were very happy with, but also gave them warning that if they took that same approach with the wrong company they could easily find themselves charged with a crime.

Re: I Hacked into Facebook's Legal Department Admin Panel

#177

Earlier quoted context omitted.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

I macro agree with your point about leverage although I'd like a bit more insight here... "You can give them a hint as to what it is, to vouch for the legitimacy of your finding, but Facebook has one of the better-resourced security teams in the industry, and they're just going to find it themselves and shut it down without paying you anything." Wouldn't that cost Facebook much more than $7,000?

The bug bounty program and the salary of the security team likely come out of different budgets.

The middle manager who cares a lot about staying “on budget” for bounties could care less how long it takes the security team to track down a bug.

Re: I Hacked into Facebook's Legal Department Admin Panel

#178

Earlier quoted context omitted.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

I’d suggest anybody planning on making demands during a bug disclosure get some advice from a lawyer first. If you use the wrong phrasing, it’s very easy to end up committing extortion or blackmail. I had some young college students report a very clever bug to me a few years ago, and they chose to take a rather aggressive approach when it came to discussing the bounty. We paid them a sum they were very happy with, bu…

Props to you and your team for treating them fairly and knowing how to council in such a difficult position.

Re: I Hacked into Facebook's Legal Department Admin Panel

#180
post #65

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

2%? You have an interesting idea of the world's population. Just think about what that means. It means 2 out of 100 people can hack into Facebook's Legal Department Admin Panel. I mean if we are talking "mentally capable to achieve that within a decade if the person does nothing else but strive to that goal"... Perhaps. If we are talking "sit down right now and do it", then it's more like what... 10,000-100,000 peopl…

Woo hoo! I'm in the top 100k in the world for something ;)
Post reply on HN