Holy heck, $12.5K? That's one heck of a nice bug bounty program Facebook has there. That is likely more than the black market would pay for this, or at least a lot less hassle (plus the black market might have little interest as this cannot be used for hijackings, just trolling/harrassment).
I doubt the "black market" would pay much of anything for this bug, because, like most severe web vulnerabilities, it has no half-life.
Deleting any Facebook album
21–30 of 107 posts
Re: Deleting any Facebook album
#22If $12,500 seems like a lot of money, remember that Facebook theoretically loses $22,453 for every minute their website is down. In other words, they generate $12,500 every 33 seconds. Paying out that sum of money to increase the number of people searching for security flaws is quite smart.
Re: Deleting any Facebook album
#23This isn't one of those vulnerabilities that relies on numerous seemingly unrelated steps and makes you wonder how the person ever thought it up.
Instead, this is security 101 stuff. Facebook simply wasn't making sure userFor(appKey) == owner(albumId). I would've assumed obvious holes like this don't even exist in the API. So, props to the author trying it out. Wish I had.
Re: Deleting any Facebook album
#24I'm not 100% sure on this, could you only delete albums for users who had given access to your app, or was it any user at all?
Re: Deleting any Facebook album
#25Earlier quoted context omitted.
I doubt the "black market" would pay much of anything for this bug, because, like most severe web vulnerabilities, it has no half-life.
What do you mean by "half-life" in this context ?
The half-life of this bug is ~0. As soon as Facebook becomes aware of it, it is nearly instantly fixed everywhere. This is very not the case if you get e.g. code execution on a version of Java which will take 50 months to completely disappear from the wild.
Re: Deleting any Facebook album
#26Holy heck, $12.5K? That's one heck of a nice bug bounty program Facebook has there. That is likely more than the black market would pay for this, or at least a lot less hassle (plus the black market might have little interest as this cannot be used for hijackings, just trolling/harrassment).
It's not very useful to compare bug bounty payouts to what the "black market" would pay for a vulnerability. Let's look through the challenges of selling a vulnerability that allows for arbitrary account takeover (much more serious than this): 0. Find the vulnerability. Assume that no one will find it by the time you find a third party buyer. 1. Look for a buyer. If you're not well-connected, you might stumble into a…
Re: Deleting any Facebook album
#27If $12,500 seems like a lot of money, remember that Facebook theoretically loses $22,453 for every minute their website is down. In other words, they generate $12,500 every 33 seconds. Paying out that sum of money to increase the number of people searching for security flaws is quite smart.
Re: Deleting any Facebook album
#28If $12,500 seems like a lot of money, remember that Facebook theoretically loses $22,453 for every minute their website is down. In other words, they generate $12,500 every 33 seconds. Paying out that sum of money to increase the number of people searching for security flaws is quite smart.
Re: Deleting any Facebook album
#29Good work. I see a lot of people are surprised at the amount received for this report. Yes, that is typical of both Facebook and Google (and to a lesser extent, Yahoo will pay large sums for particularly bad bugs). They are extremely generous - Facebook recently paid $5000 for a bug report that existed in their careers portal despite that infrastructure being entirely third party. If anyone wants to try and replicate…
Agreed. Touch/m.facebook.com have had major holes exist for long after they have been plugged on the main site. It was iframeable long after the main site wasn't (and thus subject to clickjacking). Also, for a long time you could invite anyone to events by Facebook ID by posting the correct calls to the mobile site, essentially without limit, even after the issue was fixed on the main site. Since custom messages could be embedded in the invitations, it was a spam free-for-all.
Re: Deleting any Facebook album
#30If $12,500 seems like a lot of money, remember that Facebook theoretically loses $22,453 for every minute their website is down. In other words, they generate $12,500 every 33 seconds. Paying out that sum of money to increase the number of people searching for security flaws is quite smart.
$ 12,500 is not a lot of money for this kind of work, if he is hired to find the same bugs he will earn much more.