Remote Code Execution on a Facebook server
81–90 of 207 posts
Re: Remote Code Execution on a Facebook server
#82The fact that the machine has a hostname "*.thefacebook.com" doesn't imply that it also runs software of the "Facebook" social media software. So not sure how much impact this exploit would have had.
Re: Remote Code Execution on a Facebook server
#83Re: Remote Code Execution on a Facebook server
#84The fact that the machine has a hostname "*.thefacebook.com" doesn't imply that it also runs software of the "Facebook" social media software. So not sure how much impact this exploit would have had.
I don't think anyone will ever know how much impact, but it implies that Facebook is not good at security.
Re: Remote Code Execution on a Facebook server
#85> scanning an IP range that belongs to Facebook (199.201.65.0/24) ping -4 facebook.com results in 157.240.18.35. Maybe, author used some other way to get those IPs. Can anyone throw a light on this?
Re: Remote Code Execution on a Facebook server
#86Wow, a fix in <24 hours, that's pretty impressive.
30.07.2018 00:00 CEST : initial disclosure with every details.
09.08.2018 18:10 CEST : patch in place.
Re: Remote Code Execution on a Facebook server
#87I'll have to remember this next time I think an exploit scenario is too unlikely.
Re: Remote Code Execution on a Facebook server
#88> I found a Sentry service hosted on 199.201.65.36 I do not remember on top of my head now but I think there are few scanning software to find all the running apps on a remote machine. If you are aware then please share
Re: Remote Code Execution on a Facebook server
#89Re: Remote Code Execution on a Facebook server
#90He got $5k for an arbitrary remote execution bug? What a rip-off.
Regardless, I feel like he deserves at least $15,000 for this, since it is full RCE.