Earlier quoted context omitted.
The academic difference is quite distinct and is well understood in the research community there. Impressive vulnerabilities that could take down all of Google wouldn’t be accepted into any security research conferences/journals if the bug didn’t involve a new class of vulnerability or discovery method. The term “bug prospector” might not be widely accepted, but people just looking for well understood bugs in product…
Vulnerability researchers aren't generally academic researchers. "Vulnerability research" is a term of art.
I Hacked into Facebook's Legal Department Admin Panel
251–260 of 301 posts
Re: I Hacked into Facebook's Legal Department Admin Panel
#252Earlier quoted context omitted.
It works sometimes . I'm not sure everyone would have the nerve to aggressively drop zero days, you don't know who you are going to cross, my paranoia would not let me. I'm also not a security person, but I am sure there are people who have the necessary skills, but have the same nerves as I have.
And then sometimes you get sued. Source: got sued by Sony for disclosing that they screwed up their ECDSA implementation so badly that you could compute their private keys (and then putting Linux back on the PS3 using that flaw). Microsoft not doing that with Xbox (orig/360) hackers is why the Xbox One has really good security. They hired them instead.
Re: I Hacked into Facebook's Legal Department Admin Panel
#253Judging my the response letter it seems they think he only managed to reset a password... not setting the password. Will be interesting to read the follow up.
That wouldn't really make sense, would it? As it allowed him to log in.
> So let’s get back to see what I’ve done here, I sent random requests using intruder with a CSRF token and random emails with a new password to this endpoint /savepassword
> Now I went to the login page and I put the login email and the new password and BOOM I logged in Successfully into the application and I can enter the admin panel
Re: I Hacked into Facebook's Legal Department Admin Panel
#254Earlier quoted context omitted.
And then sometimes you get sued. Source: got sued by Sony for disclosing that they screwed up their ECDSA implementation so badly that you could compute their private keys (and then putting Linux back on the PS3 using that flaw). Microsoft not doing that with Xbox (orig/360) hackers is why the Xbox One has really good security. They hired them instead.
How did that turn out with Sony in the end?
Re: I Hacked into Facebook's Legal Department Admin Panel
#255You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
Re: I Hacked into Facebook's Legal Department Admin Panel
#256Earlier quoted context omitted.
It works sometimes . I'm not sure everyone would have the nerve to aggressively drop zero days, you don't know who you are going to cross, my paranoia would not let me. I'm also not a security person, but I am sure there are people who have the necessary skills, but have the same nerves as I have.
And then sometimes you get sued. Source: got sued by Sony for disclosing that they screwed up their ECDSA implementation so badly that you could compute their private keys (and then putting Linux back on the PS3 using that flaw). Microsoft not doing that with Xbox (orig/360) hackers is why the Xbox One has really good security. They hired them instead.
Re: I Hacked into Facebook's Legal Department Admin Panel
#257Awesome post. Shameless plug on a similar exploit I found using the browser developer tools on a large scale application https://github.com/rukshn/rukshn.github.io/blob/master/archi...
Re: I Hacked into Facebook's Legal Department Admin Panel
#258Earlier quoted context omitted.
And then sometimes you get sued. Source: got sued by Sony for disclosing that they screwed up their ECDSA implementation so badly that you could compute their private keys (and then putting Linux back on the PS3 using that flaw). Microsoft not doing that with Xbox (orig/360) hackers is why the Xbox One has really good security. They hired them instead.
PS3 runs FreeBSD
Re: I Hacked into Facebook's Legal Department Admin Panel
#259Earlier quoted context omitted.
You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…
Why don't state actors that are explicitly aligned against the USA have public bug buying programs? Like a Russian website where you can go and submit your bug and get $250K.
Re: I Hacked into Facebook's Legal Department Admin Panel
#260Earlier quoted context omitted.
You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…
It seems like the problem is that there is disclosing as a zero day isn't seen as a credible thread, since it's generally seen as bad practice. If security researchers wanted to try and collect more they could in theory form some kind of union to keep up the price of bounties, with like a middle agent pricing the bounty and disclosing the vulnerability if the price isn't met. Maybe combine with some kind of insurance…
Sequencing plays a major role here. And while that may seem somewhat arbitrary, it is significant.
(Similar case, that, for some reason tech people have entirely too much trouble understanding: Announce "I'm going to shoot this gun at that target". Person, having heard you, walks and stands in front of the target. Are you still allowed/morally right to shoot?)