Earlier quoted context omitted.
Fantastic bug, and great writeup. Of course, everyone will be curious about the payout ;)
Well, it's already disclosed, but I really wanted to know how much people would think this kind of bug is worth.
How I found a Remote Code Execution bug affecting Facebook's servers
11–20 of 59 posts
Re: How I found a Remote Code Execution bug affecting Facebook's servers
#12Hi. I'm the one who found the bug. Facebook's side of this story is at https://www.facebook.com/BugBounty
I'm curious: how much time would you say you worked on researching and identifying this bug? BTW, I don't begrudge you the payout one little bit, no matter how long you spent on it; such an amount is change down the back of the sofa for facebook, and the potential impact of the bug means they got a great deal!
As I said in the post, I already had a strong suspicion that, once I could read files, escalating to RCE would be easy. But I decided not to do it without permission and they fixed the bug very quickly. As much as I'd loved to actually see the output of an ls or something like that, I think I made the right call.
Re: How I found a Remote Code Execution bug affecting Facebook's servers
#13Re: How I found a Remote Code Execution bug affecting Facebook's servers
#14Re: How I found a Remote Code Execution bug affecting Facebook's servers
#15Re: How I found a Remote Code Execution bug affecting Facebook's servers
#16This was very interesting. What are good reasorces to learn more about this kind of stuff?
Re: How I found a Remote Code Execution bug affecting Facebook's servers
#17Fb is so stingy with payouts.Bugs of a website with over a billion users can be sold for millions.Is fb ignoring this fact?
As discussed in the FB comments on the FB post, Google's standard RCE payout is $20,000. So FB was certainly not being stingy here.
Re: How I found a Remote Code Execution bug affecting Facebook's servers
#18Earlier quoted context omitted.
Well, it's already disclosed, but I really wanted to know how much people would think this kind of bug is worth.
After Ryan McGeehan's comment about the "million dollar bug" (cited in your writeup), I'd say your bug is worth at least $100k.
Re: How I found a Remote Code Execution bug affecting Facebook's servers
#19Fb is so stingy with payouts.Bugs of a website with over a billion users can be sold for millions.Is fb ignoring this fact?
Re: How I found a Remote Code Execution bug affecting Facebook's servers
#20Hi. I'm the one who found the bug. Facebook's side of this story is at https://www.facebook.com/BugBounty
https://www.facebook.com/BugBounty/posts/778897822124446?str...