Live data from Hacker News

Remote Code Execution in Slack desktop apps

hackerone.com

191–200 of 201 posts

Re: Remote Code Execution in Slack desktop apps

#191

Earlier quoted context omitted.

I do not have the market rates for vulnerabilities, but I do know some pen testing companies charge $10,000 for a few days of work that may not return any concrete bugs. Compared with hiring a pen testing team, offering high bounties seems like a bargain as you get actual exploits that would impact the company.

Yes, that is the premise behind bug bounties. If you're a vulnerability researcher with a track record, you will probably make better money and certainly more consistent money as a pentester. Many pentesters just do both. I have, uh, some experience with the rates here.

Can I ask, if you were the owner of the popular note taking app, what bounty would you want to have paid for that vulnerability? I.e.:

"XSS bug in a popular note taking app ... attacker to download all the users notes just by having them visit a URL"

So as to not feel worried that future vulnerabilities would get sold on the black market instead

Re: Remote Code Execution in Slack desktop apps

#192

Earlier quoted context omitted.

Yes, that is the premise behind bug bounties. If you're a vulnerability researcher with a track record, you will probably make better money and certainly more consistent money as a pentester. Many pentesters just do both. I have, uh, some experience with the rates here.

Can I ask, if you were the owner of the popular note taking app, what bounty would you want to have paid for that vulnerability? I.e.: "XSS bug in a popular note taking app ... attacker to download all the users notes just by having them visit a URL" So as to not feel worried that future vulnerabilities would get sold on the black market instead

XSS? Outside of a social network, where it can propagate itself? For a non-FAANG-scale company? Probably between $250 and $500, if it's a clean and effective XSS. Less if you have to interact with an obscure feature of the application.

Re: Remote Code Execution in Slack desktop apps

#193
post #39

I wrote that exploit & report. Just some thoughts on comments here. Sure the bounty is low, but ultimately it's their money and their decision. They will deal with the 'consequences' of others skipping their program and some public shaming. I find everyone talking about black markets etc. kind of ridiculous. Really? You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces?…

your response wrt black markets strikes me as incredibly naive knowing all the crime, murder, gross negligence causing death and corruption there is and has been literally everywhere on the planet, since forever, for money

Re: Remote Code Execution in Slack desktop apps

#194

Earlier quoted context omitted.

https://levels.fyi disagrees. I can confirm the offers on there are real

You replied to a claim about “most software” with a site that compares big tech companies, and only their US offices. The world is much bigger than your bubble.

Please omit swipes like "your bubble" from HN comments. They're against the site guidelines because they degrade the container.

https://news.ycombinator.com/newsguidelines.html

Re: Remote Code Execution in Slack desktop apps

#195
post #194

Earlier quoted context omitted.

You replied to a claim about “most software” with a site that compares big tech companies, and only their US offices. The world is much bigger than your bubble.

Please omit swipes like "your bubble" from HN comments. They're against the site guidelines because they degrade the container. https://news.ycombinator.com/newsguidelines.html

Fair, but what do you mean by “degrade the container”?

Re: Remote Code Execution in Slack desktop apps

#196
post #194

Earlier quoted context omitted.

Please omit swipes like "your bubble" from HN comments. They're against the site guidelines because they degrade the container. https://news.ycombinator.com/newsguidelines.html

Fair, but what do you mean by “degrade the container”?

I mean that they poison the conditions for community. Does that make sense?

Re: Remote Code Execution in Slack desktop apps

#197
post #185

Earlier quoted context omitted.

Lots. Many more than you’d expect. To believe otherwise is privilege. It took many years to understand this.

Dude, if somebody out there somewhere is seriously doing that, they really need some education in effective careers to pursue. That's a lot more likely to improve their lives than complaints about the social effects of the size of bug bounty payouts. Speaking of privilege, how much privilege is there in believing that ethics aren't important, because you don't know what it's like to live in a place that never even pr…

I'm sure you didn't mean to but telling people who are doing the best they can with the tools that they have that they "really need some education" comes across as incredibly condescending. It's been my experience that you will have a hard time convincing other people if you tell them things that way.

Re: Remote Code Execution in Slack desktop apps

#198
post #79
post #73

Earlier quoted context omitted.

> You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces? Jesus, not everything is about money If you haven't had food for a few days everything is indeed about money. Either you reward someone properly for the work that they can do or they'll find someone else who does. I doubt most people get fuzzy warm feelings helping a big US corporation that's too greedy to actuall…

> If you haven't had food for a few days everything is indeed about money I doubt anybody capable of finding an exploit like this is in that situation

I'm very capable of finding exploits in what can only be described as terrible living conditions and I've done so while being categorically incapable of finding food anywhere. That's not the environment I live in today (and I'm happy about it), but it really doesn't require a nice warm home with a stable internet connection to find some glaring holes in an application.

Re: Remote Code Execution in Slack desktop apps

#199
post #94

Earlier quoted context omitted.

I suggest you try and peek outside your bubble then. Software Engineering isn't free money everywhere.

You seem to be arguing against a straw man. Nobody said software engineering is free money, I said that a software engineer with the knowledge, skills and tools necessary to find an exploit like this is definitely not starving. In pretty much every country in the world, someone with those skills will be better off than 90% of the population

This is simply wrong. The fact that it is impossible for you to believe otherwise should inform you that you do indeed live inside a bubble.

Re: Remote Code Execution in Slack desktop apps

#200
post #100
post #73

Earlier quoted context omitted.

> You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces? Jesus, not everything is about money If you haven't had food for a few days everything is indeed about money. Either you reward someone properly for the work that they can do or they'll find someone else who does. I doubt most people get fuzzy warm feelings helping a big US corporation that's too greedy to actuall…

If you haven't had food in a few days, there are many better ways to get food on the table than trying to find exploitable vulnerabilities and sell them for tens of thousands of dollars, including - Work on a bounty program that rewards mitigations instead of exploits (e.g., https://www.google.com/about/appsecurity/patch-rewards/ ). Those are much more deterministic. (But there's no black market for them.) - Get a co…

Are you seriously telling people who are starving to "get a [conventional or not] job"? I'm struggling to understand your point of view, this is almost a caricature.
Post reply on HN