Live data from Hacker News

Remote Code Execution in Slack desktop apps

hackerone.com

141–150 of 201 posts

Re: Remote Code Execution in Slack desktop apps

#141

Earlier quoted context omitted.

I found a XSS bug in a popular note taking app. It would allow an attacker to download all the users notes just by having them visit a URL. I reported it on HackerOne, it was only after I refused to post it on their free program that they added me to their paid private one. It was marked as "medium", I got $250 for it.

Do you disagree with the severity? I assess it to have a 6.5 (medium) CVSS score. https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L...

I realise it’s a medium on that scale and I cannot argue otherwise.

But I think how private that data is to the end user should also be taken into account. It’s a medium for technical risk (relative to server remote exec), but it should be seen as a high priority for the company and rewarded as such.

If an end user were to ask that company “why did you leak all my private data” their response would be “your data is worth less than $250 in human labour and is seen as a medium security risk”?

Re: Remote Code Execution in Slack desktop apps

#142

Earlier quoted context omitted.

I found a XSS bug in a popular note taking app. It would allow an attacker to download all the users notes just by having them visit a URL. I reported it on HackerOne, it was only after I refused to post it on their free program that they added me to their paid private one. It was marked as "medium", I got $250 for it.

That's a pretty normal price for an XSS.

Dropbox and co pay $10,000 for the same exploit.

Re: Remote Code Execution in Slack desktop apps

#143
post #53
post #50

Earlier quoted context omitted.

I agree with you. It's super low, but I and others will just ignore it in the future and ultimately they lose. However, bug bounties are not a job. Nobody is forced or obligated to do anything. I'm giving them 'a pass' in the future :) It's great people are discussing this and surely it will improve things for future researchers. I consider bug bounties like competitions. The 'prize money' is defined beforehand. You…

What you do, though, is objectively more valuable to Slack than you were paid. They have reframed security as the competition you mention, but the stakes are much higher and they're sidestepping with this issue of "responsible reporting".

Payments from a company are subjective not objective. There is a single purchaser, in this case Slack, and the researcher already said that he wouldn't engage in unethical behaviour to make more money. Just sell the vulnerability to Slack, and be done with it.

Business owners of failing businesses, when they go to sell, many times think, "I've put in a million hours for this, so I need a million dollars." But, that will never happen.

Re: Remote Code Execution in Slack desktop apps

#144

Earlier quoted context omitted.

I found a XSS bug in a popular note taking app. It would allow an attacker to download all the users notes just by having them visit a URL. I reported it on HackerOne, it was only after I refused to post it on their free program that they added me to their paid private one. It was marked as "medium", I got $250 for it.

Do you disagree with the severity? I assess it to have a 6.5 (medium) CVSS score. https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L...

CVSS is a ouija board and you can make it say whatever you want, which is why very few practitioners take it seriously.

Re: Remote Code Execution in Slack desktop apps

#145

Earlier quoted context omitted.

That's a pretty normal price for an XSS.

Dropbox and co pay $10,000 for the same exploit.

Then you should sell it to Dropbox, because $10,000 is extremely high for an XSS vulnerability.

Re: Remote Code Execution in Slack desktop apps

#146
post #140

Earlier quoted context omitted.

> whatever you think is fair Please give us some examples of what you would consider fair in this situation.

Hours worked for the exploit * 50$ should be enough.

The researcher would probably get paid even less, if that is the case.

The value of an exploit has nothing to do with the development time.

Re: Remote Code Execution in Slack desktop apps

#147

Earlier quoted context omitted.

Unfortunately, we live in a world governed by money as a motivator. While you might not be in it for the money, many people are, to a certain degree (you know, to make a living and to be able to afford a decent life). If companies are unwilling to pay anything remotely close to what researchers' time is worth, then they shouldn't wonder when people prefer to sell the exploits that they find to those who do value thei…

So, what is the right thing to do if you find a vulnerability in Slack?

Open disclosure on day 0 it would seem.

Re: Remote Code Execution in Slack desktop apps

#148
post #14

Earlier quoted context omitted.

Had the researchers (unethically) published it as a zero-day vulnerability in e.g. a blog post stating "the slack payout wasn't enough for us to care" - what would've been their legal risks? I assume that would be _one_ way to get companies to care more about rewarding people who spend substantial amounts of time researching their security

A friend of mine swears that you can be sued for 'business damages' over improper disclosure. Sadly, the US is a non-permissive environment so I tend to believe it.

In many cases that is correct, but in practice this will never happen.

Re: Remote Code Execution in Slack desktop apps

#149
post #140

Earlier quoted context omitted.

> whatever you think is fair Please give us some examples of what you would consider fair in this situation.

Hours worked for the exploit * 50$ should be enough.

That's silly.

If someone spends 100 hours coming up with, say a clickjacking vuln, it does not magically make it worth $5000. If someone spends 6 minutes coming up with zero-click sandbox bypass in chrome, its not just worth $5.

Severity matters not time, especially in a bug bounty. If you want the stability (and assurance) of actually getting paid reasonsbly and consistently for this you should get a job as a pentester.

Re: Remote Code Execution in Slack desktop apps

#150
post #140

Earlier quoted context omitted.

> whatever you think is fair Please give us some examples of what you would consider fair in this situation.

Hours worked for the exploit * 50$ should be enough.

That's kind bad - first of all 50$ can be really low depending on the region, but more importantly this disregards the time spend on looking for exploits that don't pan out.

So I would multiply that 50$ by at least 4.

But still like the other said bugs should pay by severity not by time spent.

Post reply on HN