Live data from Hacker News

Facebook vulnerability 2013

khalil-sh.blogspot.com

271–280 of 301 posts

Re: Facebook vulnerability 2013

#271
post #213
post #34

Earlier quoted context omitted.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

From a PR perspective, here are the rules: 1. Apologize 2. Pay the guy 3. Spell out in clear,vanilla English the steps to take to report bugs. Don't be a fucking macho/idiot. No need to dig in your heels when u already shot yourself in the foot by saying right out of the gate that it was not a bug.

Agreed: Shreateh could have used/sold the bug to anyone, however he chose to bring it to the attention of FB. Knowing they didn't have enough information [to claim it as a bug or NOT as a bug] from him they could have requested it instead of ignoring it. Despite the fact he used it to post on Z'bergs wall, in his mind he that wa sthe most articulate way for him to show them what it does. Clearly he had no intentions of hacking his account further else he wouldn't have declared who he was. To be outraged by the fact he was desperately bringing this bug to FB's attention is ridiculous and you should be thankful. Instead showing reasons to not pay him are ungrateful and seem deliberate. Dude brought to you a decent hack, sort him out.

Re: Facebook vulnerability 2013

#272
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

I worked in FB before so I understand that it's kind impossible to track all the bugs/reports received without clear information provided. However, you can easily tell this guy is humble and not really trying to show off, it's the one who simple wrote "this is not a bug", instead of asking for more information, putting him to actually hack Mark's page.

For a better PR, pay him and use this case as an example to teach the future whitehats. FB has low esteem for a reason.

Re: Facebook vulnerability 2013

#273
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

With all respect, obviously you was able to reproduce the bug and fix it. Maybe you forget, that language barrier to Palestine can be an issue too, so because you make not clear what you asking for, when he send you back a link. Obviously it is more work to post on Mark Zuckerbergs Page than respond in the way you want.

Plus i am very sure, the mistake was on Facebook ends in the first place. I experienced it myself: Since 6 month now i try that Facebook take action, because the break of privacy issues and violation of Facebook terms by a Facebook user - i even not give an response on any channel in tried.

If you really do not give him his reward for the Report and keep you informed, than this is extremely unfair from facebook end. IN this case i strongly recommend WhiteHat Hackers in future cases: Do not count on Facebook Team, publish bugs and security issues on Blogs. Obviously the Facebook team give priority not based if a problem is urgent, only how "public" it is.

Frank

Re: Facebook vulnerability 2013

#274
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

Although, Mr. Shreateh did not follow the Facebook TOC to the letter, as written by Facebook's legal team, he did operate in good faith, according to the Yahoo article, quoted below. Whether or not Facebook legally owes Mr. Shreateh $500 + change or not, the potential PR costs and being "cheap" image is one I would hope does not attach itself to Facebook - leave that to Walmart.

"So when a security researcher named Khalil Shreateh from Palestine found a bug that let him post stuff to other people's Walls, he reported it to Facebook.

That bug is a spammer's dream. To prove his bug was real, Shreateh posted something to Sarah Goodin's wall, a friend of Facebook CEO Mark Zuckerberg.

He then contacted Facebook's security team with the proof that his bug was real, he explained in a lengthy blog post. Facebook has a bounty program where it pays people to report bugs instead of using them or selling them on the black market. In this case, instead of fixing the bug and paying the researcher the $500+ fee, Facebook told him "this was not a bug," according to an email that Shreateh shared.

Shreateh says he tried a second time to warn Facebook and when that didn't work, he used the bug to post a message to Mark Zuckerberg's Wall."

Re: Facebook vulnerability 2013

#275
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

Lol. Khalil next time post a bug of facebook in the black market and then they will pay better.

Re: Facebook vulnerability 2013

#276
post #76

Earlier quoted context omitted.

"As you can see at https://www.facebook.com/whitehat , in order to qualify for a payout you must "make a good faith effort to avoid privacy violations" and "use a test account instead of a real account when investigating bugs." I just looked at it, then switched Facebook to Arabic and the TOS is magically still in English (edit - and right aligned really badly as the page evidently expects arabic). If you demand that…

They can't pay people to violate their terms of use or to try to violate the privacy of their users. Even if they wanted to, they're probably not allowed to do that.

You must be Mark Zuckerberg

Re: Facebook vulnerability 2013

#277
post #76

Earlier quoted context omitted.

"As you can see at https://www.facebook.com/whitehat , in order to qualify for a payout you must "make a good faith effort to avoid privacy violations" and "use a test account instead of a real account when investigating bugs." I just looked at it, then switched Facebook to Arabic and the TOS is magically still in English (edit - and right aligned really badly as the page evidently expects arabic). If you demand that…

They can't pay people to violate their terms of use or to try to violate the privacy of their users. Even if they wanted to, they're probably not allowed to do that.

Good point.

Lesson learned: Find a security hole, report it to Facebook, and they don't respond after two attempts? Sell it as a zero day.

Incentives matter. And there is always money to be had somewhere else.

Re: Facebook vulnerability 2013

#278
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

Facebook - value themselves at $100bn, value their customers and developers as dirt. Very unclassy.

Re: Facebook vulnerability 2013

#279
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

You guys should hire the guy since he showed the world what a big flaw that was, instead of selling it he kept on trying to tell to the company. He should be seen as a hero by Facebook!

Shows how many issues there should be that are not taken into account.

BTW: English not being the primary language for these folks has not to do with anything, shows how much stereotype there's in being American or not. It's a global world, wake up!

BR,

Re: Facebook vulnerability 2013

#280

Have to agree with everyone here. The first email gives enough information to base a case on. Enough to simply do a quick search and verify these people aren't friends. I get less information than this from users for a product we support, it's frustrating, but if you don't investigate each lead as a potential you run the risk of having it snowball. Shame on Facebook for dismissing this guy's reward due to the lazy ac…

How does the first email contain enough information to base a case on? All he says is that he can post links to other people's walls. He makes absolutely no mention of not being the target's friend.

Why would he be reporting it to whitehat if it was expected behavior?
Post reply on HN