Live data from Hacker News

How I found a Remote Code Execution bug affecting Facebook's servers

ubercomp.com

1–10 of 59 posts

Re: How I found a Remote Code Execution bug affecting Facebook's servers

#4
post #3

Hi. I'm the one who found the bug. Facebook's side of this story is at https://www.facebook.com/BugBounty

Fantastic bug, and great writeup. Of course, everyone will be curious about the payout ;)

Well, it's already disclosed, but I really wanted to know how much people would think this kind of bug is worth.

Re: How I found a Remote Code Execution bug affecting Facebook's servers

#5

Hi. I'm the one who found the bug. Facebook's side of this story is at https://www.facebook.com/BugBounty

I'm curious: how much time would you say you worked on researching and identifying this bug? BTW, I don't begrudge you the payout one little bit, no matter how long you spent on it; such an amount is change down the back of the sofa for facebook, and the potential impact of the bug means they got a great deal!

Re: How I found a Remote Code Execution bug affecting Facebook's servers

#9
post #7

Fb is so stingy with payouts.Bugs of a website with over a billion users can be sold for millions.Is fb ignoring this fact?

As discussed in the FB comments on the FB post, Google's standard RCE payout is $20,000. So FB was certainly not being stingy here.
Post reply on HN