Live data from Hacker News

Deleting any Facebook album

7xter.com

71–80 of 107 posts

Re: Deleting any Facebook album

#71

It seems like Facebook's Bug Bounty Program payment processor bugbountypayments.com is down http://isup.me/bugbountypayments.com . Anyone have any experience with that site? I haven't heard of it coming up before in security program discussions on HN or elsewhere.

works over https https://www.bugbountypayments.com

Wonder if it's intentional, i.e.: If you are truly L337 then you'd work it out eventually, or it's some sort of HSTS type-thing.

Re: Deleting any Facebook album

#72
post #44

sorry if this is trivial, but how easy is it to get the Mobile API access token? I thought api access tokens should be safeguarded like credentials

You didn't need the target's access token. Your own worked just fine.

Woah, didn't catch that when I first skimmed through the article. $12,500 wasn't enough then.

Re: Deleting any Facebook album

#73
post #23

Is anyone else kind of shocked that this particular vulnerability exists given that Facebook employs "the best and brightest" in the industry? This isn't one of those vulnerabilities that relies on numerous seemingly unrelated steps and makes you wonder how the person ever thought it up. Instead, this is security 101 stuff. Facebook simply wasn't making sure userFor(appKey) == owner(albumId). I would've assumed obvio…

Mistakes happen. When you're pen-tested for the first time (by a decent pen-tester) you go through the 5 Stages of Grief with the stuff they find.

Re: Deleting any Facebook album

#74
post #67

Earlier quoted context omitted.

Yet there's no way to tell FB about problems without having an account (that I could find in 5 minutes). I found potential phishing attempts in the Windows Store, suggested apps right from the start menu. MS refuses to do anything about phishing/scams on their store, and FB offers no way to contact them (I tried a few email addresses like legal@, to no response).

You can (and preferably should) use a Whitehat Test Account to perform your research/make your report: https://www.facebook.com/whitehat/accounts/ apps.facebook.com (Facebook Windows Store) is not in the scope of this bug bounty program though.

I'm just trying to let FB know of a potential phishing attempt that's targeting all Windows users. I don't care about the bounty, in fact I only care a: to teach MS a lesson and b: to annoy the "developers" scamming people. I don't care enough to sign up for FB. Every other company I've dealt with on this, except some of the large media companies, have been easy enough to contact about the problem.

To be clear, the issue is: Windows users using the Windows search feature, or directly using the Windows Store, are presented with fake FB apps claiming to be official. Contacting MS support gets useless replies, as they are trying to pump their app counts. Meanwhile, normal users end up installing a potentially malicious app, claiming to be the official FB app. FB needs to send a takedown.

Re: Deleting any Facebook album

#75
post #47

Earlier quoted context omitted.

For the seriousness of this bug 12k doesn't seem like much to me. I don't know if I would turn it in for that little. With my personal dislike of facebook, the alternative is so very, very tempting..

That alternative being...

Short FB, delete everyone's photos, buy FB.

Re: Deleting any Facebook album

#76
Didn't anyone else find this post suspicious ?

I browsed through the site thinking there were some other interesting security posts.

Turns out this is the only post on the site. Then I did a Whois and this site was created 2 days ago. It's registered to laksshmanan51@gmail.com which is apparently the same guy on the post. Then I did a search on Google for laksshmanan51@gmail.com and there are search results with "You can earn huge using your Facebook page. Please let me know if you are interested. Shoot me a mail laksshmanan51@gmail.com"

This just doesn't pass the smell test with me, seems to me this guy just pwned a lot of people to get ad clicks or something else.

Re: Deleting any Facebook album

#77
post #67

Earlier quoted context omitted.

You can (and preferably should) use a Whitehat Test Account to perform your research/make your report: https://www.facebook.com/whitehat/accounts/ apps.facebook.com (Facebook Windows Store) is not in the scope of this bug bounty program though.

I'm just trying to let FB know of a potential phishing attempt that's targeting all Windows users. I don't care about the bounty, in fact I only care a: to teach MS a lesson and b: to annoy the "developers" scamming people. I don't care enough to sign up for FB. Every other company I've dealt with on this, except some of the large media companies, have been easy enough to contact about the problem. To be clear, the i…

things might have changed over the past 12 months, but if you report an app from the store app in windows 8, the report gets looked at and they were good about removing apps that had issues.

I say this since I went through this process myself about a year ago and the app I reported was taken down. full disclosure: I worked on the app store team, but didn't use any internal mechanism.

Re: Deleting any Facebook album

#78
post #2

Nice! Easy $12500. I'm kicking myself but then again, who woulda thunk?

I think this post is a hoax. A lot of things don't add up.

I thought there would be more interesting security posts and this is the only post on the entire site.

The site was registered just 2 days ago, see http://www.whois.com/whois/7xter.com . Then if you search on Google for the email that registered the site (laksshmanan51@gmail.com) you get this http://apnahindisms.blogspot.mx/2014/09/bewafa-shayari-in-hi... that has "You can earn huge using your Facebook page. Please let me know if you are interested. Shoot me a mail laksshmanan51@gmail.com"

Re: Deleting any Facebook album

#79
post #11

Good work. I see a lot of people are surprised at the amount received for this report. Yes, that is typical of both Facebook and Google (and to a lesser extent, Yahoo will pay large sums for particularly bad bugs). They are extremely generous - Facebook recently paid $5000 for a bug report that existed in their careers portal despite that infrastructure being entirely third party. If anyone wants to try and replicate…

I think this post is a hoax. A lot of things don't add up. I thought there would be more interesting security posts and this is the only post on the entire site. The site was registered just 2 days ago, see http://www.whois.com/whois/7xter.com . Then if you search on Google for the email that registered the site (laksshmanan51@gmail.com) you get this http://apnahindisms.blogspot.mx/2014/09/bewafa-shayari-in-hi.... that has "You can earn huge using your Facebook page. Please let me know if you are interested. Shoot me a mail laksshmanan51@gmail.com"

Re: Deleting any Facebook album

#80

If $12,500 seems like a lot of money, remember that Facebook theoretically loses $22,453 for every minute their website is down. In other words, they generate $12,500 every 33 seconds. Paying out that sum of money to increase the number of people searching for security flaws is quite smart.

> Facebook theoretically loses $22,453 for every minute their website is down.

Any reference for this?

Post reply on HN