How I found a Remote Code Execution bug affecting Facebook's servers
1–10 of 59 posts
Re: How I found a Remote Code Execution bug affecting Facebook's servers
#2Hi. I'm the one who found the bug. Facebook's side of this story is at https://www.facebook.com/BugBounty
Re: How I found a Remote Code Execution bug affecting Facebook's servers
#3Hi. I'm the one who found the bug. Facebook's side of this story is at https://www.facebook.com/BugBounty
Fantastic bug, and great writeup.
Of course, everyone will be curious about the payout ;)
Re: How I found a Remote Code Execution bug affecting Facebook's servers
#4Hi. I'm the one who found the bug. Facebook's side of this story is at https://www.facebook.com/BugBounty
Fantastic bug, and great writeup. Of course, everyone will be curious about the payout ;)
Well, it's already disclosed, but I really wanted to know how much people would think this kind of bug is worth.
Re: How I found a Remote Code Execution bug affecting Facebook's servers
#5Hi. I'm the one who found the bug. Facebook's side of this story is at https://www.facebook.com/BugBounty
I'm curious: how much time would you say you worked on researching and identifying this bug? BTW, I don't begrudge you the payout one little bit, no matter how long you spent on it; such an amount is change down the back of the sofa for facebook, and the potential impact of the bug means they got a great deal!
Re: How I found a Remote Code Execution bug affecting Facebook's servers
#6The payment was apparently USD 33'500.
Not being in the bug bounty business, I had expected a higher payment.
Re: How I found a Remote Code Execution bug affecting Facebook's servers
#7Fb is so stingy with payouts.Bugs of a website with over a billion users can be sold for millions.Is fb ignoring this fact?
Re: How I found a Remote Code Execution bug affecting Facebook's servers
#8Extremely interesting (and open) write-up reginaldo. Congratulations on the payout.
Re: How I found a Remote Code Execution bug affecting Facebook's servers
#9Fb is so stingy with payouts.Bugs of a website with over a billion users can be sold for millions.Is fb ignoring this fact?
As discussed in the FB comments on the FB post, Google's standard RCE payout is $20,000. So FB was certainly not being stingy here.
Re: How I found a Remote Code Execution bug affecting Facebook's servers
#10Congratulations Reginaldo - great read, great story from A-Z. Don't worry about the payout. Apparently you got brains and a white hat, that's all you need for a carefree life.