Live data from Hacker News

Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

arabcrunch.com

11–20 of 81 posts

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#11
post #8

In my opinion..I think they should compensate him.They said he violated their terms...Their terms on the whitehat page is not even localised for other Languages. Too Bad.

In his first message, he demonstrates that his bug exists by showing that he exploited somebody elses account. This is obviously, never the way to make a bug report. Heck, it's probably even illegal. You shouldn't need to read a sites terms and conditions to know that doing this will be breaking them. It's an expensive lesson. Hopefully it will lead to him being more sensible in future. I have no sympathy.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#12
Not that my comment is related to this post specifically, but I just want to clarify something. ArabCrunch (which founder's ArabGeek on HN) is known for his super weird conspiracy theory views on everything, including that he's being targeted specifically, check this: http://is.gd/0BxLrc and http://is.gd/zXroDO. Also, he uses his website as a tool to link to jihadi websites promoting violence against non-moslems. Check his post congratulating moslems this passing Ramadan [on the arabic version of the site]: http://is.gd/tT5xTb (the link in question is the first one and it's called منبر التوحيد والجهاد which translates to "Tawhid and Jihad platform".

And yes, this is not my account. I created it specifically to post this.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#13
post #7

Earlier quoted context omitted.

"----Original Message to Facebook----- From: kha @hotmail.com To: Subject: post to facebook users wall . Name: Ḱhalil E-Mail: khal @hotmail.com Type: privacy Scope: www Description: dear facebook team . my name is khalil shreateh. i finished school with B.A degree in Infromation Systems . i would like to report a bug in your main site (www.facebook.com) which i discovered it . repro: the bug allow facebook users to s…

No wonder they ignored the bug report. It looks like a spam e-mail. Why no proper capitalization? Why is your education relevant?

English isn't his first language.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#14
Re: "We are unfortunately not able to pay you for this vulnerability because your actions violated our Terms of Service."

Poor Zuck, literally poor poor Zuck. #Sarcasm

Prediction: People will start finding holes, shorting the stock, exploiting the holes, then going public with the exploit and making their money once the stock dips.

Done correctly, that probably pays pretty damn well, yes?

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#15
post #8

In my opinion..I think they should compensate him.They said he violated their terms...Their terms on the whitehat page is not even localised for other Languages. Too Bad.

In his first message, he demonstrates that his bug exists by showing that he exploited somebody elses account. This is obviously , never the way to make a bug report. Heck, it's probably even illegal. You shouldn't need to read a sites terms and conditions to know that doing this will be breaking them. It's an expensive lesson. Hopefully it will lead to him being more sensible in future. I have no sympathy.

He also gave no technical information at all. He gave more info on his education than the bug he found.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#17
I applaud him for his expertise and finding the bug but here are some points Ḱhalil:

- You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that.

- I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken the time to clearly explain the steps. For example you have said "mark profile" instead of "Mark Zuckerberg's profile". That's just ambiguous language and confuses the reader. They probably receive a lot of wrong reports every day so if you make mistakes like that you are less likely to be taken seriously.

- After they said it is not a bug, it is clear that they have misunderstood you because you failed to communicate clearly. You could write a more detailed report and tell them that they have misunderstood you. If not you could report in your first language and let them ask one of their Arabic-speaking employees.

- You violated the terms again by exploiting the bug on Mark's profile. It would be bad if it was any other Facebook user too. But you went straight for Mark which will obviously generate a lot of buzz and negative publicity and I'm sure he doesn't appreciate someone randomly posting something on his wall.

- Just because they fail to receive your bug report does not make it ok for you to go ahead and exploit it.

By exploiting the bug you had found twice you lose your whitehat status and you no longer deserve the bounty. Whitehat does not mean "white hat unless you fail to take my report then I will have to exploit your CEO's profile for the world to see".

If Facebook does pay you for the bug, it is just setting a bad example and will be encouraging similar behaviour.

After that, every other person who finds a bug too will do something funny to Mark's profile for attention.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#18

Re: "We are unfortunately not able to pay you for this vulnerability because your actions violated our Terms of Service." Poor Zuck, literally poor poor Zuck. #Sarcasm Prediction: People will start finding holes, shorting the stock, exploiting the holes, then going public with the exploit and making their money once the stock dips. Done correctly, that probably pays pretty damn well, yes?

Uh, no. How many security exploits do you think would impact Facebook's stock? This one? Investors do not care about minor bugs that are fixed quickly.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#19
post #3

He did that after facebook security team rejected his request to report a bug

That doesn't automatically make it ok for him to go ahead and exploit someone's profile for attention (for the 2nd time). He wrote a lazy report and knew they did not understand him. He could write a more detailed report and tell them that they have misunderstood him. Or he could write one in Arabic and ask them to get help from one of the Arabic-speaking employees.

After two messages back and forth, he says "i have no choice other than report this to mark himself". He did indeed have many other choices but he jumped straight to posting on Mark's profile which he knew will create a global shit-storm.

It's clear he wasn't very reluctant to posting on Mark's profile anyway. He was just waiting for them to ignore him so he can drop his "i have no other choice" line and go ahead.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#20
post #17

I applaud him for his expertise and finding the bug but here are some points Ḱhalil: - You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that. - I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken…

The author clearly has a language barrier. Not all bug reports are going to come with sterling reports to back them. In the end, Ḱhalil fell back on the lingua franca of the internet: a working demonstration.

The onus is on the organization, not the bug reporter, to vet the information. From what I see, there was more than enough in the report to conclude there was a problem, and follow up.

If Facebook security fails in coding the application, in QR, and when a user files a bug report, it is awfully hard to place the blame with the bug reporter.

Post reply on HN