Stealing Facebook access_tokens using CSRF in device login flow
josipfranjkovic.com
Stealing Facebook access_tokens using CSRF in device login flow
1–10 of 89 posts
Re: Stealing Facebook access_tokens using CSRF in device login flow
#2Re: Stealing Facebook access_tokens using CSRF in device login flow
#3Re: Stealing Facebook access_tokens using CSRF in device login flow
#4so you got paid $5,000 ? How long since the first report did it take for that to reach your bank account?
Re: Stealing Facebook access_tokens using CSRF in device login flow
#5so you got paid $5,000 ? How long since the first report did it take for that to reach your bank account?
The bug was reported on December 8th, 2015 and fixed on February 18th, 2016 which is an unusually long time for Facebook. The bounty reached my account during the middle of March, but Facebook has recently changed their bounty payment processor to Bugcrowd, and now they have weekly payments.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#6I think $5,000 is a joke, this is a serious vulnerability... Despite this, congratulations for finding it and reporting directly to them, the right way. If it's possible to know, how many hours did you spend researching this?
Re: Stealing Facebook access_tokens using CSRF in device login flow
#7I think $5,000 is a joke, this is a serious vulnerability... Despite this, congratulations for finding it and reporting directly to them, the right way. If it's possible to know, how many hours did you spend researching this?
I tend to agree. They should probably add a zero to that.
Obviously $5,000 is a lot of money, but not to Facebook, and especially not in the context of fixing serious vulnerabilities on a platform that has 1.65B users.
If Facebook paid more they'd enhance their security in the process, at the cost of what amounts to chump change for them.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#8Re: Stealing Facebook access_tokens using CSRF in device login flow
#9Earlier quoted context omitted.
The bug was reported on December 8th, 2015 and fixed on February 18th, 2016 which is an unusually long time for Facebook. The bounty reached my account during the middle of March, but Facebook has recently changed their bounty payment processor to Bugcrowd, and now they have weekly payments.
Weekly payments as opposed to a lump sum? Why? I can't imagine cashflow is an issue for them.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#10Earlier quoted context omitted.
The bug was reported on December 8th, 2015 and fixed on February 18th, 2016 which is an unusually long time for Facebook. The bounty reached my account during the middle of March, but Facebook has recently changed their bounty payment processor to Bugcrowd, and now they have weekly payments.
Weekly payments as opposed to a lump sum? Why? I can't imagine cashflow is an issue for them.