Live data from Hacker News

I found Prezi's source code

blog.shubh.am

21–30 of 266 posts

Re: I found Prezi's source code

#21
post #18
post #15

Earlier quoted context omitted.

To be fair, there was a scope set, and the author was fully aware of it: > I had spent a total of 2 hours sifting and crawling through their services which were in scope, but wanted to see if I could locate any other subdomains, with the assistance of google. While I agree that he most certainly found a "bug" (perhaps flaw would be a better word), it was out of scope. And using credentials from an employee to log in…

That said, he could have gone "gray-hat" and used the source to find in-scope bugs. Such a resource would be invaluable to an exploit author or bug bounty hunter.

Legally, I don't think there's much "gray" in stealing source code that doesn't belong to you.

Re: I found Prezi's source code

#22
Ignoring the bounty thing for a second, their email response "we think it was in good faith" seems... Not right to me. Am i reading that weird or did they seem pissed about him finding something like that?

He plugged a huge issue for them, and they screw him over due to "scope"... That's their choice, but it still seems bureaucratic to me.

Re: I found Prezi's source code

#23
What this guy describes doing (using accidentally exposed credentials to log in to somewhere) is quite a bit more than what other people have been successfully prosecuted for violations of the CFAA for. I'd be careful.

Re: I found Prezi's source code

#24
One wonders if he wouldn't have been better[1] off downloading their app source, and using that to find 'in-scope' vulns much easier than everyone else. They might catch on if you're too effective though. Maybe a spot of plausible parallel construction.

[1] Except for the totally illegal aspect, obviously. And the not-telling-them-their-source-is-open-to-the-world bit.

Re: I found Prezi's source code

#25
post #19

> "Anyways, they did try and get it right, by emailing me an apology as well as responding to my constructive criticism. This blog post, is by no means attempting to discourage people from participating from Prezi’s bug bounty, but rather just a blog post about how finding Prezi’s source code was not eligible for their bug bounty." Passive aggressive much? I think he should have got a bounty -- if not the official on…

Probably doesn't want anybody pointing legal fingers at him for harming Prezi or something.

Oh I see. You mean like, "Here's my experience; I decided to stop participating. But I'm not advising you to. Offer not valid in all areas. Yada yada..."

Re: I found Prezi's source code

#27
post #10

It was out of scope. The rules are pretty clear: http://prezi.com/bugbounty/ and he broke at least two of them. And it seems like he knew it was out of scope when he submitted it too: "I had spent a total of 2 hours sifting and crawling through their services which were in scope , but wanted to see if I could locate any other subdomains..." Now I think Prezi should probably have paid him anyway because that's a prett…

Sometimes people and companies have their heads stuck so far in procedures and policies that they can't see the forests from the trees.

The Finder provided tremendous value by discovering this issues and reporting it responsibly. He certainly should be rewarded with something more substantial than swag.

Would Prezi have preferred that the Finder just not report this issues?

Re: I found Prezi's source code

#28
post #21
post #18

Earlier quoted context omitted.

That said, he could have gone "gray-hat" and used the source to find in-scope bugs. Such a resource would be invaluable to an exploit author or bug bounty hunter.

Legally, I don't think there's much "gray" in stealing source code that doesn't belong to you.

> Legally, I don't think there's much "gray" in stealing source code that doesn't belong to you

I thought the whole point of gray hat is that it's possibly illegal, but not downright "evil".

i.e. Stealing source code to fix bugs = gray, stealing source code to steal credit card info = black

Re: I found Prezi's source code

#29
post #20

Exhibit A of why having a scope for bug bounties is a terrible idea. What is the point of testing your app for esoteric bugs when your entire source code and passwords can be Google dorked?

> Exhibit A of why having a scope for bug bounties is a terrible idea.

Case closed.

Post reply on HN