Live data from Hacker News

Facebook vulnerability 2013

khalil-sh.blogspot.com

221–230 of 301 posts

Re: Facebook vulnerability 2013

#221
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

This is just bad PR for FB all around. You guys handled this poorly. It's obvious the OP held no ill intentions when he posted on MZ's wall - if anything he seemed to have been driven to it in order to get your attention to a serious bug which your team specifically claimed not to be a bug. Your ungrateful response is typical of a large corporation only out to save face.

Re: Facebook vulnerability 2013

#222
post #199

Earlier quoted context omitted.

Demonize the security team? I never implied that anywhere - please don't "put words in my mouth."

I think you are here: https://news.ycombinator.com/item?id=6231466 . And please don't bother defending, just dropping by.

K. I won't point out to you why you're mistaken.

Re: Facebook vulnerability 2013

#223
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

FB should pay him double - or more - no telling how much he's saved the company by revealing the incompetence within the sec team.

Too bad FB doesn't have the graciousness to be thankful that the researcher didn't exploit what its security team deemed as dismissive.

Re: Facebook vulnerability 2013

#225
post #5

Note to security response teams everywhere: Not all vulnerability reporters speak perfect English, nor are they all experienced in writing up details on how to exploit issues. It is your responsibility to obtain details from reporters, after the initial report, to avoid situations like this. Facebook should give a bug bounty here, due to their lack of due diligence in following up with the initial responses.

Lets hope that OP doesn't have anymore security vulnerabilities in hand because if he do, FB will pay the price of not paying him for the first time :)

Re: Facebook vulnerability 2013

#228
post #15

After watching the video, it looks like the exploit involves: 1) Getting the target user's userId. This used to be part of a user's profile URL but Facebook allowed people to choose a "vanity URL" quite a while ago, so they're no longer as visible. So, instead, the userId is obtained from a FB Graph API query. 2) The form that makes up the "post to newsfeed" has a bunch of hidden inputs. One of them refers to a "xhpc…

This is a pretty vicious error but common one...it sounds like the analogue to Rails' mass-assignment default protections, which were exploited on Github by tampering with the params via inspector. Coincidentally, that bug was also exposed by a non-native English speaker who was dismissed for his inability to fluently express himself. http://homakov.blogspot.com/2012/03/how-to.html

no, i was dismissed for some other reason. My emails (i reread them a while ago) explained perfectly where's the bug.

On this topic: i still have no clue what vulnerability it was. Guy, do you know such terms XSS, CSRF etc? Can't u just say where's the bug, nobody wants to watch 6 (!) minutes long video with arabic subtitles rofl. peace

Re: Facebook vulnerability 2013

#229
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

Pay the man. He did you a you favor. Stop with all this jibber jabber regarding TOS. He could have used this security flaw to do damage. Instead he posted his name etc. "Rules are Rules" are for people too dumb to think. Pay up. Man you guys and gals who don't want to pay sound like a bunch of parrots. All you know is how to repeat words. THINK

Re: Facebook vulnerability 2013

#230
taking into account fogginess of emails of the researcher and amount of emails FB whitehat receives daily... I am not surprised they said it's not a bug.

PROTIP: Reports should have PoC and be concise. No information about your bachelor degree should be attached.

Post reply on HN