Live data from Hacker News

Facebook vulnerability 2013

khalil-sh.blogspot.com

1–10 of 301 posts

Re: Facebook vulnerability 2013

#3
Looks like if you edit facebook in firebug while you are posting a link to your newsfeed you can change the source userid which is not validated/checked and gets posted even though you dont have the permission to do it

Re: Facebook vulnerability 2013

#4
So they get the exploit and fix it without paying the person who found it. These kinds of actions lead exploit finders to instead pursue rewards through the black market. Very sad indeed.

Re: Facebook vulnerability 2013

#5
Note to security response teams everywhere: Not all vulnerability reporters speak perfect English, nor are they all experienced in writing up details on how to exploit issues. It is your responsibility to obtain details from reporters, after the initial report, to avoid situations like this. Facebook should give a bug bounty here, due to their lack of due diligence in following up with the initial responses.

Re: Facebook vulnerability 2013

#6
post #5

Note to security response teams everywhere: Not all vulnerability reporters speak perfect English, nor are they all experienced in writing up details on how to exploit issues. It is your responsibility to obtain details from reporters, after the initial report, to avoid situations like this. Facebook should give a bug bounty here, due to their lack of due diligence in following up with the initial responses.

Yeah, what the hell were they doing responding "This is not a bug." without investigating or asking for more details? What the hell is the point of even responding to possible security alerts from the general public if you're not going to investigate?

Re: Facebook vulnerability 2013

#8
post #2

Just as your disclosure emails provide almost no information whatsoever, your blog post was also pretty devoid of useful explanation.

> I found an exploit, here's proof, but I'm having difficulty conveying information due to linguistic barriers.

> Nope that's not a bug.

What did you expect him to do? Learn English on the fly? Conveying specific technical things is a difficult skill to learn even for native English speakers.

Sure his communication isn't the best, but neither is "I can't click that link" nor "This isn't a bug."

Re: Facebook vulnerability 2013

#9
The OPs English is not excellent (but way better than my Arabic)...but I'd be interested in hearing the FB responder's rationale for dismissing the initial submission. Language barrier aside, the link and the image provided should speak for themselves.

But perhaps the bug-hotline gets so much spam that the OP came off as junk email to the FB dev team? Just skimming over his email, I'm struck by how much poor punctuation and capitalization triggers my mental spam alert (and that's before even reading the actual contents).

Post reply on HN