Earlier quoted context omitted.
You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…
It seems like the problem is that there is disclosing as a zero day isn't seen as a credible thread, since it's generally seen as bad practice. If security researchers wanted to try and collect more they could in theory form some kind of union to keep up the price of bounties, with like a middle agent pricing the bounty and disclosing the vulnerability if the price isn't met. Maybe combine with some kind of insurance…
I Hacked into Facebook's Legal Department Admin Panel
271–280 of 301 posts
Re: I Hacked into Facebook's Legal Department Admin Panel
#272Earlier quoted context omitted.
You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…
Is it legal to do this? Post on Twitter that you've asked Company X for this bounty and if they don't pay it by Date X you'll post it on Twitter. If they don't pay it, post the bug on Twitter. Is that as legal as posting the bug on Twitter straightaway, which as I understand is legal?
But whether it's legal or not, it won't work. Facebook will likely never do business with you again, but they'll watch your Twitter account for the free bugs you're promising to give them.
Re: I Hacked into Facebook's Legal Department Admin Panel
#273Earlier quoted context omitted.
>> Which is essentially market driven blackmail as far as I can see. Modern medicine can also be like blackmail. Nobody has to actually threaten you, but nature will kill you unless you pay whatever the price of treatment. That's why we need competition, and why pharma companies like monopolies.
That statement is so true it's terrifying.
Re: I Hacked into Facebook's Legal Department Admin Panel
#274Earlier quoted context omitted.
You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…
The market for random serverside bugs doesn't have to be liquid, it just has to exist I think you could flip this on White House Market pretty quick and pretty well. Either partner up with someone willing to risk their rep, or just sell 99 cent tutorials for a week and get your rep up. Or resell fullz lol And then come in with the much larger payload and a few forum posts about it They only use Monero for payments an…
If your bug generates OG Instagram accounts, you'll probably find a buyer --- they will be loons who are likely to land you a prison sentence, because that's the general caliber of person who commits felonies to briefly lock up short account names on Instagram, and you'll have absolutely no way of arguing in court that you didn't know exactly what they were going to do. But you'll probably sell it, because there is an existing business process that acquires OG Instagram accounts your bug can slot into.
Nobody has a business process for exploiting access to a stupid internal legal dashboard application. Nobody is going to shell out more than $7000, speculatively, for access to this website.
Re: I Hacked into Facebook's Legal Department Admin Panel
#275Earlier quoted context omitted.
You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…
I think if the guy that came to the internal google documents a few years back, would offer the content on the donation based web site and prove they are genuine, it might get more out of donations from various privacy groups / people than he got from google for the vulnerability. Same goes here. It is not about the vulnerability, it is about the content.
Re: I Hacked into Facebook's Legal Department Admin Panel
#276Earlier quoted context omitted.
IANAL, but: The classic situation of blackmail is demanding money from someone, or else you'll reveal some embarrassing fact about them, report that they committed some crime, etc. Saying "Give me money or I will publicly disclose a bug in your computer systems" – that fits the classic situation of blackmail straight on. Saying "Fix this bug in 90 days or I'll publicly reveal it" – doesn't fit the classic situation o…
As you've described it, blackmail shouldn't be a crime when revealing the information would be otherwise legal.
The act being threatened – reporting your crime to the police – is totally legal, even socially encouraged. It is only the demanding of money (or other benefits) not to do it part which is the crime of blackmail.
If I just went ahead and reported your crime to the police – no crime of blackmail.
If I just didn't – no blackmail (but could be some other crime, such as misprision)
It's only when I tell you that whether I'm going to do it depends on whether you do something for me that blackmail has been committed.
Re: I Hacked into Facebook's Legal Department Admin Panel
#277Earlier quoted context omitted.
3) is how you get the real money. Dropping zero days like its hot works and will lead to a good paying job. Example: https://nakedsecurity.sophos.com/2019/06/13/microsofts-battl... wah wah bad person publishing zero days wah wah Irresponsible disclosure hurts everyone. wah wah reality: https://krebsonsecurity.com/2020/04/microsoft-patch-tuesday-... got hired @Microsoft, started fixing other bugs they didnt know they…
It works sometimes . I'm not sure everyone would have the nerve to aggressively drop zero days, you don't know who you are going to cross, my paranoia would not let me. I'm also not a security person, but I am sure there are people who have the necessary skills, but have the same nerves as I have.
Re: I Hacked into Facebook's Legal Department Admin Panel
#278Awesome post. Shameless plug on a similar exploit I found using the browser developer tools on a large scale application https://github.com/rukshn/rukshn.github.io/blob/master/archi...
Interesting post, but I have troubles understanding the "SSL vulnerability with the exposed IP address" part. SSL does not prevent knowing IP addresses...
Re: I Hacked into Facebook's Legal Department Admin Panel
#279Earlier quoted context omitted.
It's sort of implied that it's not Burp Intruder, but Burp Intruder would be a pretty normal way to do this.
It's actually Burpsuite, you can tell from the screenshot he provided.
Re: I Hacked into Facebook's Legal Department Admin Panel
#280Earlier quoted context omitted.
It’s that second part. “I’m going to do x if you don’t y.” He’s under no obligation to disclose. But the second part is coercion. x itself might also constitute a crime.
Using an "if" doesn't mean coercion if first action is legitimate - I'm going to refuse your offer if you don't propose something better. - I'm going to work on it if you don't want to - I'm going to eat the cake if don't like it
It is coercion. But not all coercion is criminal.