Nice! Easy $12500. I'm kicking myself but then again, who woulda thunk?
Deleting any Facebook album
31–40 of 107 posts
Re: Deleting any Facebook album
#32Earlier quoted context omitted.
It's not very useful to compare bug bounty payouts to what the "black market" would pay for a vulnerability. Let's look through the challenges of selling a vulnerability that allows for arbitrary account takeover (much more serious than this): 0. Find the vulnerability. Assume that no one will find it by the time you find a third party buyer. 1. Look for a buyer. If you're not well-connected, you might stumble into a…
In a week, an attacker with an account-takeover exploit could attack every high-profile celebrity and likely dig up enough dirt on them to get far more than $50,000 in hush money. Or they could go the old-fashioned route and use it to snoop on the plans of wealthy people to kidnap them and hold them for ransom. There are many, many possibilities for making money if you can gain access to anyone's facebook account, ev…
I'm not asking if you can hypothesize such a market. I'm asking if you know about one actually existing.
It's been suggested to me that there is in fact at least one set of buyers for account takeover bugs. But they aren't monetizing those accounts.
Re: Deleting any Facebook album
#33If $12,500 seems like a lot of money, remember that Facebook theoretically loses $22,453 for every minute their website is down. In other words, they generate $12,500 every 33 seconds. Paying out that sum of money to increase the number of people searching for security flaws is quite smart.
Re: Deleting any Facebook album
#34Earlier quoted context omitted.
$ 12,500 is not a lot of money for this kind of work, if he is hired to find the same bugs he will earn much more.
While this is absolutely true, I know some people that like to do this type of stuff for "fun" and the bounty is just icing on the cake. It also won't hurt him in finding that kind of work in the future.
"I made $10k just for a quick hack"[1] has enormous bragging value - it's both a large enough payout for that, and it can actually be used without going to jail. Much better than actually bringing Facebook down.
[1] It doesn't matter how much work went into finding the exploit, one can still brag about doing it left-handed in 5 minutes.
Re: Deleting any Facebook album
#35Holy heck, $12.5K? That's one heck of a nice bug bounty program Facebook has there. That is likely more than the black market would pay for this, or at least a lot less hassle (plus the black market might have little interest as this cannot be used for hijackings, just trolling/harrassment).
It's a great incentive to not sell it on the black market.
Re: Deleting any Facebook album
#36If $12,500 seems like a lot of money, remember that Facebook theoretically loses $22,453 for every minute their website is down. In other words, they generate $12,500 every 33 seconds. Paying out that sum of money to increase the number of people searching for security flaws is quite smart.
Yet there's no way to tell FB about problems without having an account (that I could find in 5 minutes). I found potential phishing attempts in the Windows Store, suggested apps right from the start menu. MS refuses to do anything about phishing/scams on their store, and FB offers no way to contact them (I tried a few email addresses like legal@, to no response).
Re: Deleting any Facebook album
#37Earlier quoted context omitted.
In a week, an attacker with an account-takeover exploit could attack every high-profile celebrity and likely dig up enough dirt on them to get far more than $50,000 in hush money. Or they could go the old-fashioned route and use it to snoop on the plans of wealthy people to kidnap them and hold them for ransom. There are many, many possibilities for making money if you can gain access to anyone's facebook account, ev…
Do you have firsthand or even secondhand knowledge of a market for account takeover bugs where the buyers are monetizing those bugs via celebrity dirt? Do you have knowledge of markets for account takeover where buyers are directly monetizing those bugs at all? I'm not asking if you can hypothesize such a market. I'm asking if you know about one actually existing. It's been suggested to me that there is in fact at le…
Re: Deleting any Facebook album
#38If $12,500 seems like a lot of money, remember that Facebook theoretically loses $22,453 for every minute their website is down. In other words, they generate $12,500 every 33 seconds. Paying out that sum of money to increase the number of people searching for security flaws is quite smart.
$ 12,500 is not a lot of money for this kind of work, if he is hired to find the same bugs he will earn much more.
These sorts of things are publicly verifiable - Michal Zalewski has commented on it before as a member of the Google appsec team, and if you look on Twitter for writeups from the same folks you come to the same conclusion. I have in mind one particular friend who literally bankrupted a bug bounty in three hours.
Another security researcher by the name of Nicholas Gregoire earned $35,000 combined from Yahoo and Facebook for a single vulnerability in each company - both server-side request forgery. He found it in Yahoo's YQL console, then decided to look elsewhere for it in a very deterministic fashion, and came across it in Parse (Facebook). He found many more bugs in a period of a few months, but he explicitly didn't look as seriously as some people do, which entails actively tracking acquisitions by companies like Google and Facebook.
It can be something of a meat grinder, but finding bug bounties is extremely profitable work. Then of course, having this work on a rèsumè is an immediate step up for getting interviews.
Re: Deleting any Facebook album
#39Holy heck, $12.5K? That's one heck of a nice bug bounty program Facebook has there. That is likely more than the black market would pay for this, or at least a lot less hassle (plus the black market might have little interest as this cannot be used for hijackings, just trolling/harrassment).
It's not very useful to compare bug bounty payouts to what the "black market" would pay for a vulnerability. Let's look through the challenges of selling a vulnerability that allows for arbitrary account takeover (much more serious than this): 0. Find the vulnerability. Assume that no one will find it by the time you find a third party buyer. 1. Look for a buyer. If you're not well-connected, you might stumble into a…