Earlier quoted context omitted.
Yeah, what the hell were they doing responding "This is not a bug." without investigating or asking for more details? What the hell is the point of even responding to possible security alerts from the general public if you're not going to investigate?
I am curious to how many trash reports they have to sort through to identify real bug reports. Anyone care to comment?
Facebook vulnerability 2013
21–30 of 301 posts
Re: Facebook vulnerability 2013
#22Re: Facebook vulnerability 2013
#23Re: Facebook vulnerability 2013
#24Wow, upvoting this and I really hope it goes viral and FB gets called out for it. Hopefully he can get the bug bounty he deserves. That's incredibly sleazy of FB to treat him this way.
Re: Facebook vulnerability 2013
#25After watching the video, it looks like the exploit involves: 1) Getting the target user's userId. This used to be part of a user's profile URL but Facebook allowed people to choose a "vanity URL" quite a while ago, so they're no longer as visible. So, instead, the userId is obtained from a FB Graph API query. 2) The form that makes up the "post to newsfeed" has a bunch of hidden inputs. One of them refers to a "xhpc…
They're still visible in photo albums and the like. Far from hidden.
Re: Facebook vulnerability 2013
#26I find it harsh of Facebook that without technical leverage they do not pay out bounties.
Re: Facebook vulnerability 2013
#27Earlier quoted context omitted.
Yeah, what the hell were they doing responding "This is not a bug." without investigating or asking for more details? What the hell is the point of even responding to possible security alerts from the general public if you're not going to investigate?
I am curious to how many trash reports they have to sort through to identify real bug reports. Anyone care to comment?
Re: Facebook vulnerability 2013
#28Re: Facebook vulnerability 2013
#29The TOS stuff i think i a bit shity. Partly cause they made him do it(more than necessary)