Holy heck, $12.5K? That's one heck of a nice bug bounty program Facebook has there. That is likely more than the black market would pay for this, or at least a lot less hassle (plus the black market might have little interest as this cannot be used for hijackings, just trolling/harrassment).
I doubt the "black market" would pay much of anything for this bug, because, like most severe web vulnerabilities, it has no half-life.
Deleting any Facebook album
41–50 of 107 posts
Re: Deleting any Facebook album
#42Earlier quoted context omitted.
In a week, an attacker with an account-takeover exploit could attack every high-profile celebrity and likely dig up enough dirt on them to get far more than $50,000 in hush money. Or they could go the old-fashioned route and use it to snoop on the plans of wealthy people to kidnap them and hold them for ransom. There are many, many possibilities for making money if you can gain access to anyone's facebook account, ev…
Do you have firsthand or even secondhand knowledge of a market for account takeover bugs where the buyers are monetizing those bugs via celebrity dirt? Do you have knowledge of markets for account takeover where buyers are directly monetizing those bugs at all? I'm not asking if you can hypothesize such a market. I'm asking if you know about one actually existing. It's been suggested to me that there is in fact at le…
Re: Deleting any Facebook album
#43If $12,500 seems like a lot of money, remember that Facebook theoretically loses $22,453 for every minute their website is down. In other words, they generate $12,500 every 33 seconds. Paying out that sum of money to increase the number of people searching for security flaws is quite smart.
Re: Deleting any Facebook album
#44sorry if this is trivial, but how easy is it to get the Mobile API access token? I thought api access tokens should be safeguarded like credentials
Re: Deleting any Facebook album
#45Earlier quoted context omitted.
$ 12,500 is not a lot of money for this kind of work, if he is hired to find the same bugs he will earn much more.
I understand your sentiment here, but that's a difficult comparison. Friends of mine make more money hunting bug bounties each year than their (competitive) full time salaries as consultants or developers. These sorts of things are publicly verifiable - Michal Zalewski has commented on it before as a member of the Google appsec team, and if you look on Twitter for writeups from the same folks you come to the same con…
Re: Deleting any Facebook album
#46Earlier quoted context omitted.
I doubt the "black market" would pay much of anything for this bug, because, like most severe web vulnerabilities, it has no half-life.
No, but imagine the ressources they would have had to throw at the problem if the user had instead decided to delete ALL the photo albums on the site. Or imagine if he would have used the exploit to delete all the photos of a movie launch, etc. The reward is appropriate.
Re: Deleting any Facebook album
#47If $12,500 seems like a lot of money, remember that Facebook theoretically loses $22,453 for every minute their website is down. In other words, they generate $12,500 every 33 seconds. Paying out that sum of money to increase the number of people searching for security flaws is quite smart.
For the seriousness of this bug 12k doesn't seem like much to me. I don't know if I would turn it in for that little. With my personal dislike of facebook, the alternative is so very, very tempting..
Re: Deleting any Facebook album
#48Re: Deleting any Facebook album
#49What do you do when you think a company would just fix the bug based on your report and not pay out anything? I have seen so many bugs in the wild like this. For example a site in the uk where I can get access to any account I wish.
Are there any data protection laws that would provide leverage? How would you make first contact with a company that doesn't advertise a bug bounty program?
Does this kind of email seem ok?
"Hi, I have seen a security vulnerability on your site. How do I report it? What do you pay?…
May you respond in the next 7 days or I will be forced to take this to xxx.org for the protection of your users"Re: Deleting any Facebook album
#50So here seems like as good a thread as any. What do you do when you think a company would just fix the bug based on your report and not pay out anything? I have seen so many bugs in the wild like this. For example a site in the uk where I can get access to any account I wish. Are there any data protection laws that would provide leverage? How would you make first contact with a company that doesn't advertise a bug bo…
Edit: I should probably expand on that. Telling a company that you know about a bug but won't tell them about it if they don't pay you and instead threaten to turn it over to other parties who may have more nefarious intentions is pretty much extortion and is likely illegal.
I understand that you'd want to make money out of it, but if the company offers no bug bounty, it's no good threatening them. If you do so, it'll likely trigger a hostile response.