Live data from Hacker News

Facebook vulnerability 2013

khalil-sh.blogspot.com

131–140 of 301 posts

Re: Facebook vulnerability 2013

#131
post #87

Earlier quoted context omitted.

Firstly, no idea how you can conclude he hacked an account. A bit strong of language there? Second, does reason not come into play here? You don't have to write a policy to compensate people for violating privacy - however if you have a human making decisions, and not just a drone following written orders, then the ability to make compromises exist. Just no one at Facebook wants to engage and be human it seems.

> Firstly, no idea how you can conclude he hacked an account. A bit strong of language there? This is like... the textbook definition of a hack. > however if you have a human making decisions, and not just a drone following written orders, then the ability to make compromises exist. Just no one at Facebook wants to engage and be human it seems. I love that this statement is downthread of a Facebook engineer's comment…

>> Firstly, no idea how you can conclude he hacked an account. A bit strong of language there?

>This is like... the textbook definition of a hack.

Perhaps of "hacking FB", but he didn't "hack an account".

I don't see what the problems are for FB here. They have a moral obligation to reward him for reporting this bug, especially since their ToS are apparently not available in Arabic. Claiming that he showed any sort of malicious/inappropriate behavior is a really bad tactic to save some money when they clearly handled this very badly from the start, while his intentions were obviously good.

All they are achieving by reacting this way (including the apologets) is that next time, such people will just sell their exploits on the blackhat market.

Re: Facebook vulnerability 2013

#132
post #78
post #45

Earlier quoted context omitted.

Pay the man. He stumbled around a bit trying to work out how to help, but he brought a flaw to your attention in what he thought was a polite way. If unleashed, this bug could've been used to wreak havoc on Facebook and damage the company's reputation. $500 is the very least FB should be paying.

Is it even lawful for them to pay people that knowingly invade other people's accounts?

They will pay for reporting of the bug. What's with the apparently intentionally inaccurate description of his actions? All he did was post to someone's wall, that's hardly "invading someone's account".

Re: Facebook vulnerability 2013

#133
If I was this guy, I would rather say screw it than trying to get attention by posting to Mark's wall. Given the recent cases in the USA (e.g. he used wget!!!), Facebook could give a massive slap and sue him. And probably win.

Re: Facebook vulnerability 2013

#134
To all the commenters that think Facebook should pay this guy: he became "the guy who hacked Mark Zuckerberg ON Facebook" overnight. I guess that this will probably open some doors for him, and if not, he's still become famous. :)

Maybe Mark should just hire the guy to replace the initial bug responder.

Re: Facebook vulnerability 2013

#135
post #134

To all the commenters that think Facebook should pay this guy: he became "the guy who hacked Mark Zuckerberg ON Facebook" overnight. I guess that this will probably open some doors for him, and if not, he's still become famous. :) Maybe Mark should just hire the guy to replace the initial bug responder.

haha yeah.

Re: Facebook vulnerability 2013

#136
post #25

After watching the video, it looks like the exploit involves: 1) Getting the target user's userId. This used to be part of a user's profile URL but Facebook allowed people to choose a "vanity URL" quite a while ago, so they're no longer as visible. So, instead, the userId is obtained from a FB Graph API query. 2) The form that makes up the "post to newsfeed" has a bunch of hidden inputs. One of them refers to a "xhpc…

This used to be part of a user's profile URL but Facebook allowed people to choose a "vanity URL" quite a while ago, so they're no longer as visible. They're still visible in photo albums and the like. Far from hidden.

Correct. Sorry, didn't mean to imply it was hard to obtain this value (the switch to vanity URL part was more of an anecdote) but just to describe what happened in the video of the exploit.

Re: Facebook vulnerability 2013

#137
post #5

Note to security response teams everywhere: Not all vulnerability reporters speak perfect English, nor are they all experienced in writing up details on how to exploit issues. It is your responsibility to obtain details from reporters, after the initial report, to avoid situations like this. Facebook should give a bug bounty here, due to their lack of due diligence in following up with the initial responses.

And to go further, Facebook has an office in Dubai. [0] Are you telling me if language was not a barrier, they could not find a single Arabic-speaking employee? They could even save money on the collect calls, if Facebook was not an option.

And hats off to Khaled. Hebron is not a fun place to grow up, and making it that far, a B.S. that is, is an accomplishment. I grew up with far more privilege and I am still not smart enough to come up with Facebook exploits.

[0] https://www.facebook.com/careers/locations/dubai

Re: Facebook vulnerability 2013

#138
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

Why didn't your coworkers reply back asking for more info? This is like the first thing security engineers should do. Look how serious Security Engineers at Microsoft reply back, http://blogs.msdn.com/b/oldnewthing/archive/2011/12/15/10247...

The right thing to do is add Khalil to the white hat list, and pay him what he deserves. He doesn't speak or read English as you have noticed. Your TOS for white hat page is NOT even translatable.

He used real accounts because your team did not care what he had to say. What do you think he should have done? Sell it to the black market?

Re: Facebook vulnerability 2013

#140
post #45

Earlier quoted context omitted.

Pay the man. He stumbled around a bit trying to work out how to help, but he brought a flaw to your attention in what he thought was a polite way. If unleashed, this bug could've been used to wreak havoc on Facebook and damage the company's reputation. $500 is the very least FB should be paying.

after being treated this way, i doubt this man (probably everyone who read this) will ever report bugs to facebook anymore.

Agreed, Facebook will not be safe anymore. All these white hackers will sell their exploit to black hackers.
Post reply on HN