Live data from Hacker News

How I found a Remote Code Execution bug affecting Facebook's servers

ubercomp.com

11–20 of 59 posts

Re: How I found a Remote Code Execution bug affecting Facebook's servers

#11
post #3

Earlier quoted context omitted.

Fantastic bug, and great writeup. Of course, everyone will be curious about the payout ;)

Well, it's already disclosed, but I really wanted to know how much people would think this kind of bug is worth.

After Ryan McGeehan's comment about the "million dollar bug" (cited in your writeup), I'd say your bug is worth at least $100k.

Re: How I found a Remote Code Execution bug affecting Facebook's servers

#12

Hi. I'm the one who found the bug. Facebook's side of this story is at https://www.facebook.com/BugBounty

I'm curious: how much time would you say you worked on researching and identifying this bug? BTW, I don't begrudge you the payout one little bit, no matter how long you spent on it; such an amount is change down the back of the sofa for facebook, and the potential impact of the bug means they got a great deal!

Well, I originally found the OpenID bug in 2012, but hadn't noticed Facebook was vulnerable until very recently. After I found their OpenID endpoint, the hardest part was getting them to make me a Yadis discover request. Then I had to squash a little bug in the exploit. Most of the time was spent re-reading the OpenID spec. I'd say total amount of work (including the time it took me to write the post) was about 2 days.

As I said in the post, I already had a strong suspicion that, once I could read files, escalating to RCE would be easy. But I decided not to do it without permission and they fixed the bug very quickly. As much as I'd loved to actually see the output of an ls or something like that, I think I made the right call.

Re: How I found a Remote Code Execution bug affecting Facebook's servers

#16
post #14

This was very interesting. What are good reasorces to learn more about this kind of stuff?

Its hard and I wish I had more info. One thing I do know is that blogs are the worst form of information. I would think being a whiz at Javascript and PHP would be a prerequisite but maybe you just need a good understanding of different specs and protocols.

Re: How I found a Remote Code Execution bug affecting Facebook's servers

#17
post #9
post #7

Fb is so stingy with payouts.Bugs of a website with over a billion users can be sold for millions.Is fb ignoring this fact?

As discussed in the FB comments on the FB post, Google's standard RCE payout is $20,000. So FB was certainly not being stingy here.

So, both Google AND Facebook are stingy with these payouts?

Re: How I found a Remote Code Execution bug affecting Facebook's servers

#18

Earlier quoted context omitted.

Well, it's already disclosed, but I really wanted to know how much people would think this kind of bug is worth.

After Ryan McGeehan's comment about the "million dollar bug" (cited in your writeup), I'd say your bug is worth at least $100k.

A bug that lets you execute code on Facebook's servers is worth millions if not billions of dollars. You'll be rewarded with much less than that, but considering Facebook's market cap it is extraordinarily valuable.

Re: How I found a Remote Code Execution bug affecting Facebook's servers

#19
post #7

Fb is so stingy with payouts.Bugs of a website with over a billion users can be sold for millions.Is fb ignoring this fact?

Is there some basis to your "fact" of bugs being bought for millions for a social networking site? I could understand if someone found a remote execution bug on Big Bank Corp's website allowing you to transfer anyone's funds to your personal BTC wallet.
Post reply on HN