Live data from Hacker News

Facebook vulnerability 2013

khalil-sh.blogspot.com

51–60 of 301 posts

Re: Facebook vulnerability 2013

#52

After watching the video, it looks like the exploit involves: 1) Getting the target user's userId. This used to be part of a user's profile URL but Facebook allowed people to choose a "vanity URL" quite a while ago, so they're no longer as visible. So, instead, the userId is obtained from a FB Graph API query. 2) The form that makes up the "post to newsfeed" has a bunch of hidden inputs. One of them refers to a "xhpc…

If that is how it works, then it appears that Facebook have fixed it - you now see the message "message could not be posted to this wall".

[deleted]

Re: Facebook vulnerability 2013

#54
post #42

Earlier quoted context omitted.

Does it concern you that ultimately the way the OP got your attention is by posting to MZ's account? Are you sure you'd have ever "discovered" it if he hadn't? I agree that the OP didn't do a great job, but if he's submitting a vulnerability that you really want to hear about and you're ignoring him because of some miscommunication and you ding him for doing the one thing that gets your attention, you're creating an…

I think there's a spectrum between letting whitehats do anything (including violating privacy, hurting real user accounts, etc) vs. suing everyone who changes a GET param somewhere. Having a whitehat program with (IMO reasonable) guidelines around not impacting unsuspecting real users seems to me like a good balance and is fairly close to the first part of the spectrum. Obviously I don't love the end outcome, and thi…

Is creating test accounts even allowed by the Facebook ToS?

Re: Facebook vulnerability 2013

#55
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

How about looking into paying this man for his honest bug finding work? The response from FB on this is disgusting.

    "We are unfortunately not able to pay you for this     vulnerability because your actions violated our Terms of Service.  We do hope, however, that you continue to work with us to find vulnerabilities in the site. 

  We have now re-enabled your Facebook account. 

  Joshua 
  Security Engineer 
  Facebook "

Re: Facebook vulnerability 2013

#56

Wow, upvoting this and I really hope it goes viral and FB gets called out for it. Hopefully he can get the bug bounty he deserves. That's incredibly sleazy of FB to treat him this way.

I'm surprised at how many people just assume the FB sec team doesn't want to pay and therefore tries to not pay if they can get away with it. Their history of paying out is completely the opposite. I've reported several bugs and they're always extremely helpful. They're not an insurance company that wants to reduce cost by screwing over users and there is no historical evidence of that. They want to pay for bugs and…

"Using Zucks account doesn't make it more convincing from a tech perspective." - In this case, that's obviously false. The guy submitted the bug twice and the final reply was "This is not a bug." After posting to Zuckerberg's account it was subsequently fixed.

I'm sure the FB security team triages a lot of bug reports, and a few get away - hopefully they'll be better about trying to get more info (boiler plate requesting steps to replicate or a video), but beyond that no harm no foul. I can also see that they don't want to encourage researchers messing with real user data. However, if they paid him out and told him in the future, that he should provide more information and not use real accounts (or not get paid out, etc), that'd have the same effect (you know, since it already happened) w/o the bad will generated.

Instead, they didn't pay him, locked his account, and now we're reading that blog post, not only encouraging him and the people like him in the future to not submit these bugs in the future (certainly serious enough that it'd be worth discovering vs being in a 0-day marketplace), but generating way more visibility for no good reason. It's just not smart.

Re: Facebook vulnerability 2013

#57
post #54
post #42

Earlier quoted context omitted.

I think there's a spectrum between letting whitehats do anything (including violating privacy, hurting real user accounts, etc) vs. suing everyone who changes a GET param somewhere. Having a whitehat program with (IMO reasonable) guidelines around not impacting unsuspecting real users seems to me like a good balance and is fairly close to the first part of the spectrum. Obviously I don't love the end outcome, and thi…

Is creating test accounts even allowed by the Facebook ToS?

I assume he means whitehat test accounts which are created in the whitehat console, and can only interact with other whitehat accounts

Re: Facebook vulnerability 2013

#58
post #44
post #40

Earlier quoted context omitted.

> many of the reports we get are nonsense or misguided Alright, here's a preemptive question for you then. Should a logged in user be able to retrieve the email addresses of an arbitrary friend, regardless of their contact privacy setting being set to "only me"?

Hmm, wanna report at facebook.com/whitehat with more details? Please include repro instructions :).

Since when did repo stand for "reproduction" in sofware engineering term? Never heard it around here. East coast.

Re: Facebook vulnerability 2013

#59
post #25

After watching the video, it looks like the exploit involves: 1) Getting the target user's userId. This used to be part of a user's profile URL but Facebook allowed people to choose a "vanity URL" quite a while ago, so they're no longer as visible. So, instead, the userId is obtained from a FB Graph API query. 2) The form that makes up the "post to newsfeed" has a bunch of hidden inputs. One of them refers to a "xhpc…

This used to be part of a user's profile URL but Facebook allowed people to choose a "vanity URL" quite a while ago, so they're no longer as visible. They're still visible in photo albums and the like. Far from hidden.

It's not really obvious though

Re: Facebook vulnerability 2013

#60
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

"As you can see at https://www.facebook.com/whitehat, in order to qualify for a payout you must "make a good faith effort to avoid privacy violations" and "use a test account instead of a real account when investigating bugs."

I just looked at it, then switched Facebook to Arabic and the TOS is magically still in English (edit - and right aligned really badly as the page evidently expects arabic). If you demand that the TOS is followed by people who do not have English as a first language, try offering a translation.

This guy has done you all a service. The chances are that he may not have been able to clearly read the TOS that you wish him to abide by. He should get paid.

edit - hmm, was about to check the situation with other languages, however now all the buttons are in arabic so I stopped bothering after the fourth random page.

Post reply on HN