http://khalil-sh.blogspot.com/p/facebook_16.html
Facebook vulnerability 2013
khalil-sh.blogspot.com
1–10 of 301 posts
http://khalil-sh.blogspot.com/p/facebook_16.html
Facebook vulnerability 2013
khalil-sh.blogspot.com
Note to security response teams everywhere: Not all vulnerability reporters speak perfect English, nor are they all experienced in writing up details on how to exploit issues. It is your responsibility to obtain details from reporters, after the initial report, to avoid situations like this. Facebook should give a bug bounty here, due to their lack of due diligence in following up with the initial responses.
Just as your disclosure emails provide almost no information whatsoever, your blog post was also pretty devoid of useful explanation.
> Nope that's not a bug.
What did you expect him to do? Learn English on the fly? Conveying specific technical things is a difficult skill to learn even for native English speakers.
Sure his communication isn't the best, but neither is "I can't click that link" nor "This isn't a bug."
But perhaps the bug-hotline gets so much spam that the OP came off as junk email to the FB dev team? Just skimming over his email, I'm struck by how much poor punctuation and capitalization triggers my mental spam alert (and that's before even reading the actual contents).