Earlier quoted context omitted.
I agree. This was basically unrestricted access to any Facebook account. What a MASSIVE flaw. And who knows if this was already exploited in the wild? $15k is nothing at all compared to the scale of this issue...
Doesn't Facebook alert the user if it detects suspicious account login activity from an unknown location or IP?
How I could have hacked any Facebook account
111–120 of 168 posts
Re: How I could have hacked any Facebook account
#112Earlier quoted context omitted.
I agree. This was basically unrestricted access to any Facebook account. What a MASSIVE flaw. And who knows if this was already exploited in the wild? $15k is nothing at all compared to the scale of this issue...
It's not really unrestricted. Given that this is forcing the password reset, you can't silently do it, right? So anyone exploiting it knows there's a limited number of uses before people notice that their passwords are being reset by not them.
Re: How I could have hacked any Facebook account
#113beta.facebook.com and mbasic.beta.facebook.com Certificate Transparency has an interesting impact on some of the less-public servers. https://crt.sh/?q=%25.facebook.com A host of servers turn up in that list, which may similarly be less security tested than the main facebook.com site.
I'm surprised an organisation as large as Facebook don't have their own CA, and just don't issue the semi-secret stuff off the record.
Re: How I could have hacked any Facebook account
#114Earlier quoted context omitted.
During the fiasco that was the last white-hat hacker to report he'd hacked Facebook, I posted this: > Bug bounties are supposed to represent a high probability payoff of a lesser amount of money for finding a bug. This is in comparison to going the black hat sales root, where probability of sale might be lower, but the payoff might be higher. I can imagine one or two state actors who might pay top dollar to have keys…
where do people even go to start to sell an exploit? how does that kind of stuff work?
Re: How I could have hacked any Facebook account
#115Earlier quoted context omitted.
Your comments make sense in the real world, where the big threat is "criminal enterprise looking to make an illicit buck". I worry that people are too obsessed about the hypothetical specter of tremendously skilled and bored black-hats who will ruin lives for fun, rather than for a pay-off, e.g. ZF0.
>* hypothetical specter of tremendously skilled and bored black-hats who will ruin lives for fun* I'd assume having $15k to spend is a lot more fun than any enjoyment one could have by hacking someone's facebook account. You'd have to have a real vendetta against someone to value ruining their life at $15k.
Re: How I could have hacked any Facebook account
#116Earlier quoted context omitted.
Yeap, you're right. These guys at least aren't paying a bounty for Facebook/Google bugs: https://www.zerodium.com/program.html
Footnote on the graphic: *All payout amounts are chosen at the discretion of ZERODIUM and are subject to change or cancellation without notice. Translation: "Show us what you got and then we'll screw you over." Sounds like you're less likely to get screwed by an escrow service found on TOR.
Re: How I could have hacked any Facebook account
#117Earlier quoted context omitted.
During the fiasco that was the last white-hat hacker to report he'd hacked Facebook, I posted this: > Bug bounties are supposed to represent a high probability payoff of a lesser amount of money for finding a bug. This is in comparison to going the black hat sales root, where probability of sale might be lower, but the payoff might be higher. I can imagine one or two state actors who might pay top dollar to have keys…
where do people even go to start to sell an exploit? how does that kind of stuff work?
Re: How I could have hacked any Facebook account
#118Earlier quoted context omitted.
You know what people put into Facebook chats? Obligatory quote from Kanye's newest album 'The Life of Pablo': " I had a cousin that stole my laptop that I was fuckin' bitches on Paid that nigga 250 thousand just to get it from him "
You know what people put into Instant Bloomberg chats? Go try to sell an IBB bug.
Re: How I could have hacked any Facebook account
#119Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.
During the fiasco that was the last white-hat hacker to report he'd hacked Facebook, I posted this: > Bug bounties are supposed to represent a high probability payoff of a lesser amount of money for finding a bug. This is in comparison to going the black hat sales root, where probability of sale might be lower, but the payoff might be higher. I can imagine one or two state actors who might pay top dollar to have keys…
Re: How I could have hacked any Facebook account
#120Earlier quoted context omitted.
I suspect most whitehat researchers would be happier to report this vulnerability and make a nice legal reward, then delve into a black hat market for selling a vulnerability. Seems pretty win-win in this case.
Unless your name is Kevin Mitnick. Then you set up a business and play middlemen in selling them to anybody who wants to pony up for it. "When we have a client that wants a zero-day vulnerability for whatever reason, we don’t ask, and in fact they wouldn’t tell us,” Mitnick tells WIRED in an interview. “Researchers find them, they sell them to us for X, we sell them to clients for Y and make the margin in between.” h…