Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

271–280 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#271
post #184

Earlier quoted context omitted.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

It seems like the problem is that there is disclosing as a zero day isn't seen as a credible thread, since it's generally seen as bad practice. If security researchers wanted to try and collect more they could in theory form some kind of union to keep up the price of bounties, with like a middle agent pricing the bounty and disclosing the vulnerability if the price isn't met. Maybe combine with some kind of insurance…

Disclosing the vulnerability isn't a credible threat because Facebook essentially lets you disclose the vulnerability anyways. We are commenting on a thread about a dude who disclosed a vulnerability after getting a $7000 bounty.

Re: I Hacked into Facebook's Legal Department Admin Panel

#272

Earlier quoted context omitted.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

Is it legal to do this? Post on Twitter that you've asked Company X for this bounty and if they don't pay it by Date X you'll post it on Twitter. If they don't pay it, post the bug on Twitter. Is that as legal as posting the bug on Twitter straightaway, which as I understand is legal?

I doubt it's illegal, because posting a vulnerability that you found legitimately on Twitter isn't illegal. You might be dancing close to the edge by using Facebook's authorization to test their websites in an unauthorized way, which brings you back under the aegis of CFAA, but that seems a little far-fetched.

But whether it's legal or not, it won't work. Facebook will likely never do business with you again, but they'll watch your Twitter account for the free bugs you're promising to give them.

Re: I Hacked into Facebook's Legal Department Admin Panel

#273

Earlier quoted context omitted.

>> Which is essentially market driven blackmail as far as I can see. Modern medicine can also be like blackmail. Nobody has to actually threaten you, but nature will kill you unless you pay whatever the price of treatment. That's why we need competition, and why pharma companies like monopolies.

That statement is so true it's terrifying.

The thing to remember is that the universe does not care, and nobody owes us anything. That's what's really terrifying until you come to terms with it.

Re: I Hacked into Facebook's Legal Department Admin Panel

#274

Earlier quoted context omitted.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

The market for random serverside bugs doesn't have to be liquid, it just has to exist I think you could flip this on White House Market pretty quick and pretty well. Either partner up with someone willing to risk their rep, or just sell 99 cent tutorials for a week and get your rep up. Or resell fullz lol And then come in with the much larger payload and a few forum posts about it They only use Monero for payments an…

People on this subthread are talking about how you'll get caught, and maybe there's something to that, but the real reason this won't work is that nobody wants to buy your stupid auth bypass bug in a random line of business application.

If your bug generates OG Instagram accounts, you'll probably find a buyer --- they will be loons who are likely to land you a prison sentence, because that's the general caliber of person who commits felonies to briefly lock up short account names on Instagram, and you'll have absolutely no way of arguing in court that you didn't know exactly what they were going to do. But you'll probably sell it, because there is an existing business process that acquires OG Instagram accounts your bug can slot into.

Nobody has a business process for exploiting access to a stupid internal legal dashboard application. Nobody is going to shell out more than $7000, speculatively, for access to this website.

Re: I Hacked into Facebook's Legal Department Admin Panel

#275
post #238

Earlier quoted context omitted.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

I think if the guy that came to the internal google documents a few years back, would offer the content on the donation based web site and prove they are genuine, it might get more out of donations from various privacy groups / people than he got from google for the vulnerability. Same goes here. It is not about the vulnerability, it is about the content.

If you take documents from the website, you aren't looking for vulnerabilities, you're straightforwardly committing felonies. Private groups might donate to your legal defense fund, but they aren't going to pay you for documents they know it's a crime for you to have.

Re: I Hacked into Facebook's Legal Department Admin Panel

#276

Earlier quoted context omitted.

IANAL, but: The classic situation of blackmail is demanding money from someone, or else you'll reveal some embarrassing fact about them, report that they committed some crime, etc. Saying "Give me money or I will publicly disclose a bug in your computer systems" – that fits the classic situation of blackmail straight on. Saying "Fix this bug in 90 days or I'll publicly reveal it" – doesn't fit the classic situation o…

As you've described it, blackmail shouldn't be a crime when revealing the information would be otherwise legal.

A classic case of blackmail – I know you have committed a crime. I threaten to report your crime to the police unless you pay me.

The act being threatened – reporting your crime to the police – is totally legal, even socially encouraged. It is only the demanding of money (or other benefits) not to do it part which is the crime of blackmail.

If I just went ahead and reported your crime to the police – no crime of blackmail.

If I just didn't – no blackmail (but could be some other crime, such as misprision)

It's only when I tell you that whether I'm going to do it depends on whether you do something for me that blackmail has been committed.

Re: I Hacked into Facebook's Legal Department Admin Panel

#277
post #222

Earlier quoted context omitted.

3) is how you get the real money. Dropping zero days like its hot works and will lead to a good paying job. Example: https://nakedsecurity.sophos.com/2019/06/13/microsofts-battl... wah wah bad person publishing zero days wah wah Irresponsible disclosure hurts everyone. wah wah reality: https://krebsonsecurity.com/2020/04/microsoft-patch-tuesday-... got hired @Microsoft, started fixing other bugs they didnt know they…

It works sometimes . I'm not sure everyone would have the nerve to aggressively drop zero days, you don't know who you are going to cross, my paranoia would not let me. I'm also not a security person, but I am sure there are people who have the necessary skills, but have the same nerves as I have.

[deleted]

Re: I Hacked into Facebook's Legal Department Admin Panel

#278
post #257
post #179

Awesome post. Shameless plug on a similar exploit I found using the browser developer tools on a large scale application https://github.com/rukshn/rukshn.github.io/blob/master/archi...

Interesting post, but I have troubles understanding the "SSL vulnerability with the exposed IP address" part. SSL does not prevent knowing IP addresses...

And from the screenshot, that's just DNS resolution. Nothing to do with SSL.

Re: I Hacked into Facebook's Legal Department Admin Panel

#279
post #13

Earlier quoted context omitted.

It's sort of implied that it's not Burp Intruder, but Burp Intruder would be a pretty normal way to do this.

It's actually Burpsuite, you can tell from the screenshot he provided.

He's using Burp Suite for things, but writes about "fuzzing" for directories as if he's not using Burp for that (the plural on "tools" sort of suggests he's using something like dirbuster).

Re: I Hacked into Facebook's Legal Department Admin Panel

#280
post #122
post #85

Earlier quoted context omitted.

It’s that second part. “I’m going to do x if you don’t y.” He’s under no obligation to disclose. But the second part is coercion. x itself might also constitute a crime.

Using an "if" doesn't mean coercion if first action is legitimate - I'm going to refuse your offer if you don't propose something better. - I'm going to work on it if you don't want to - I'm going to eat the cake if don't like it

?

It is coercion. But not all coercion is criminal.

Post reply on HN