4 ms·
But like he said in the article, he was unable to find a clear policy that gave him the "Stop, no further" point. It may have been a bad assumption to think Fac
by phantarch 11y ago
But like he said in the article, he was unable to find a clear policy that gave him the "Stop, no further" point. It may have been a bad assumption to think Facebook was going with the Tumblr stance of "give us a thorough POC," but where should he have drawn the line in his hack and why here instead of where he did?
- oldmanjay 11y agoGetting the credentials is clearly enough to prove the point. Digging through user data is just celebrating.
- deleted 11y ago[deleted]
- dogecoinbase 11y agoWhereof one cannot speak, one should be silent. Dumping the user table is the literal next step in a standard vulnerability assessment (in order to acquire reused credentials), wasn't prohibited by the terms of FB's bug bounty program, and was crucial to the development of the bug.
- tptacek 11y agoNo, that's the next step in an external penetration test, which is not the same thing as a vulnerability assessment. In an external pentest, you get a set of netblocks and rules of engagement, and you get as far as you can. That's why it's called a "penetration test". In a vulnerability assessment, you get a target (usually an application), and you find as many flaws in that target as you can. Big annual pentests often have wide-open rules of engagements, where you (as a consultant) win big by, for instance, dumping the CEO's mail spool. But those projects also start with several meetings worth of negotiating rules of engagement. Vulnerability assessments virtually never have those rules of engagement! Nobody that I know of runs a bug bounty program on pentest norms. To do so would be grossly irresponsible, because on every network with more than 1000 hosts I've ever tested, ever, RCE behind the firewall is gameover for the whole test: you can get everything.
- dogecoinbase 11y agoYou're HN's anointed expert, so I suppose all I can say is that's not my experience. Among the many reasons bug bounties are bad ideas is that they generally fail to write clear rules -- as Facebook did. As written, what he did is not against the rules and while it may fall into some best-practices bucket you assert to be universal, that's hardly sufficient for a field in which participants can come from any background. But please, continue to defend your friend whose multi-billion company had a month to cycle their popped keys and failed to do so, then responded by threatening a researcher's employment after multiple conciliatory e-mails.
- emerongi 11y agoI agree. If there's no clear rule "all data stays in our network", dumping data is not an unreasonable move. I don't care whether some experts in their offices mull about what's alright to do in a pentest or when finding vulnerabilities for a bounty program - most people aren't experts in that sector, so better make it clear. The researcher is in the right here.
- tptacek 11y agoNot only is dumping data an unreasonable move, but it's one that will get you referred to prosecutors. That didn't happen here, but it just did happen somewhere else last week. Don't ever do that.
- emerongi 11y agoI wouldn't do that (I'd be scared to death about what would happen, even without reading this article). But I also don't find it an unreasonable move. Just make it clear - you dump data, we're going to sue you. Right now, the researcher is in the clear, even though what he did was incredibly stupid. I don't understand why a company would ever say "you can snoop around in our stuff" without very clearly stating what they can do. You're leaving open a legal loophole where a blackhat can claim to be a whitehat.
- 11y ago
- Dylan16807 11y agoHe didn't dig through user data. 60 accounts on the admin console are not users, and he did not touch the buckets with actual user data.
- onewaystreet 11y agoAt the line right above the one I quoted: > As described above, I used the web interface to gain code execution, but at this point I still hadn't actually gained access to the web interface as a normal user. He had code execution, there was no need for him to go any further.
- ErrantX 11y agoIn the absence of a clear guideline, Researcher101 should kick in; it was clearly the wrong thing to do. An apparent refusal to admit that in the write up is making it hard to put 100% support behind him. There is no excuse: dumping the user table was too far. Facebook went rather far too, of course.
- benmanns 11y agoThis wasn't the end-users table though, it was the admins table. What if there were a table called "security_keys" - would dumping that be disallowed?
- daveguy 11y agoYes. As much or more so than an end user table. You can't dump data and use dumped data acquired from a legitimate vulnerability to continue to gain access to additional resources.