14 ms·
How I could have hacked any Facebook account
- Grishnakh 11y agoVery disappointing. This guy had the ultimate power of doing so much good--bringing down Facebook in one fell swoop--and he didn't bother!
- jacquesm 11y agoVery disappointing comment. Everybody is free to choose to use facebook or not to use it. I chose not to use it, but I do not have the right or any moral obligation to stop others from using it. This guy did not have the right - and fortunately chose not to exercise it - to mess with other people's free choices in life. Besides that, the likely only effect any activity like you are suggesting would have had is that he would have ended up in jail and facebook would merrily continue.
- Zikes 11y agoSeeing as it's a brute-force per-account attack, a more accurate title would have been "How I could have hacked any Facebook account". Hacking "all of Facebook" would have been prohibitively resource-intensive for the hacker, and would likely have been caught and shut down before any real damage to the platform was done.
- ethanbond 11y agoThis alone would be enough to permanently cripple Facebook in the eyes of the public if applied "correctly." The iCloud/Fappening totally wasn't a big deal either, right? /s
- umanwizard 11y agoApple wasn't brought down by the fappening.
- dsmithatx 11y agoThe hacker could of worked with the black market. They could use a botnet to slowly hack a large percentage of FB potentially. Seeing as how they disabled rate-limiting on a pubic facing beta with user data, why assume they would notice brute forcing against beta?
- Zikes 11y agoThe attack involves resetting the user's password, which would have made the original user unable to access their own account until they reset the password back. After several such incidents were reported, Facebook likely would have cottoned on.
- dang 11y agoOk, we changed the title to say "any" rather than "all".
- Grishnakh 11y agoVery disappointing comment. Completely humorless and extremely preachy.
- haser_au 11y agoA great example of responsible disclosure, and the company acknowledging, fixing and rewarding the bug and finder. Great job to both Facebook and Anand.
- jdcarter 11y agoGood reminder here that all publicly-visible services are part of your overall attack surface, including beta sites and other things you never expect people to look at. The DROWN vulnerability from last week was similar: people disabled SSLv2 on their web servers, but not their mail servers. Very nice find: super simple but super effective. I'm glad Facebook paid up promptly.
- debacle 11y agoGood on Facebook for being so quick to reward Anand and fix the issue.
- cphoover 11y agoFrankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.
- ghayes 11y agoI suspect most whitehat researchers would be happier to report this vulnerability and make a nice legal reward, then delve into a black hat market for selling a vulnerability. Seems pretty win-win in this case.
- at-fates-hands 11y agoUnless your name is Kevin Mitnick. Then you set up a business and play middlemen in selling them to anybody who wants to pony up for it. "When we have a client that wants a zero-day vulnerability for whatever reason, we don’t ask, and in fact they wouldn’t tell us,” Mitnick tells WIRED in an interview. “Researchers find them, they sell them to us for X, we sell them to clients for Y and make the margin in between.” http://www.wired.com/2014/09/kevin-mitnick-selling-zero-day-exploits/ http://www.wired.com/2014/09/kevin-mitnick-selling-zero-day-...
- eklavya 11y agoHow is this legal?
- SturgeonsLaw 11y agoBecause he's selling to governments, who operate under the "it's not illegal when we do it" principle.
- yuncun 11y agoWhat if it's the Chinese government that's buying, would it suddenly turn illegal?
- 11y ago
- mcone 11y agoHow do companies evaluate the severity and impact of the vulnerability? I don't work in security, but it seems like this is worth more than $15,000.
- cphoover 11y agoIt certainly would be worth more to some people.
- dsacco 11y agoCompanies evaluate severity based on impact. There are different tiers of vulnerability. A vulnerability that affects a particular website is significantly less valuable than one that affects many websites. Companies like Google and Facebook actually overpay for vulnerabilities because 1) they're flush with cash and can, 2) it's excellent for goodwill in the industry, 3) it's an excellent recruiting tool and 4) it augments an already strong internal security program. If you hypothetically tried to go to the black market with this vulnerability you wouldn't even find a buyer. When Facebook patches this, it's useless, and you'd have to derive more than whatever you paid for. At this point it's a betting game - do you think you can earn back $100,000 using this exploit before Facebook catches wind of it? Conversely, vulnerabilities that are very highly valued tend to affect large numbers of websites in a format that is not easily patched. For example, many websites don't update WordPress often, which means that a vulnerability in WordPress is going to instantly get a CVE and a widespread push for awareness. Even so, it will be actionable for years.
- unknownzero 11y agoAnyone know what tool he was using in the YouTube video? This stuff is super interesting.
- fatlasp 11y agoLooks like Burp Suite. Sweet web proxy tool -- https://portswigger.net/burp/ https://portswigger.net/burp/ Free for 14 days I think.
- unknownzero 11y agoAwesome! Thanks for the link. It looks like they have a limited free forever version as well, gonna have to play with this.
- fatlasp 11y agohmm yea my memory might have adjusted it to a trial period -- looks like many of the most useful features are crippled in the free version.
- msie 11y agoSurprised that the well-paid developers at Facebook missed this vulnerability. Should inspire confidence on anyone who didn't get a job there. :-)
- dsmithatx 11y agoThis has me thinking about another possible attack. Say I don't want to hack all of Facebook or a specific account. What if I used a botnet to reset passwords and then use the six attempts randomly on each account I reset. Sure I'd only get a small percentage but, I would easily start hacking FB accounts. It's things like this that make me use 2FA as much as possible on personal data.
- orionblastar 11y ago2FA is nice unless you lose your cell phone or it gets stolen. If you ever lose your job or go homeless and can't afford a cell phone then you are locked out of your accounts. I am disabled and struggling if I miss payments I go homeless or can't pay my bills and things get shut off. For me 2FA might not work if I am down on my luck.
- dsmithatx 11y agoThere are ways around this for some things but, probably not with services like Facebook. For example with Amazon I use 2FA with a cellphone. As a backup I use a hardware token and an Admin account. If my cellphone gets stolen I pull the 2FA card out of my wallet.
- orionblastar 11y agoProvided that nobody steals your wallet and you don't lose that card.
- Pharaoh2 11y agoIn that case you use the backup codes that you had printed and put in a safe a register a new 2FA token.
- noobie 11y agoWhen setting up Google Authenticator for One Time Passcodes, you are also given a seed which can be used to resteup the app from another device.
- thrownn 11y agoOn the subject of rate limiting, what is the best way to apply it across all endpoints, APIs and resources, external and internal, with minimal effort? Usually, I see this implemented only as an afterthought, and only on endpoints deemed 'dangerous', waiting for a disaster like this to happen...
- noir_lord 11y agoIt's a defense in depth scenario but most webservers have modules for it, Apache certainly does as I've used it not sure about nginx still not used that in production.
- 010a 11y agoHacker News: Where comments can be six paragraphs long and say absolutely nothing.
- beshrkayali 11y agoRegardless of this being Facebook or not, but forget to throttle your API and this is what you get, some dude toying around with a tool just to poke holes in your thing, but I digress. If in any twisted, unrealistic, straight out of Homeland scenario where anyone high profile enough would make use of this "vulnerability" and successfully create a media "splash", and assuming Facebook security team is on top of their game, this would get patched in a week tops. Keeping an eye on average number of requests coming to their API end points, especially sensitive ones, is part of their job, not a nice-to-have. I'd even think this would actually get patched within 24 hours (since the fix isn't really that difficult). I have absolutely no care or sympathy for Facebook but yeah, 15K is a lot for something like this. It's a nice catch, that's all.
- technion 11y agobeta.facebook.com and mbasic.beta.facebook.com Certificate Transparency has an interesting impact on some of the less-public servers. https://crt.sh/?q=%25.facebook.com https://crt.sh/?q=%25.facebook.com A host of servers turn up in that list, which may similarly be less security tested than the main facebook.com site.
- nly 11y agoI'm surprised an organisation as large as Facebook don't have their own CA, and just don't issue the semi-secret stuff off the record.
- evgen 11y agoRunning a CA is a major pain, adds auditing and other requirements that are ongoing pain, and prior to the past year or so Facebook did not issue enough certificates to make the cost worthwhile. Doing this right means adding a lot of logging and access control around a few parts of the infra stack that would manage this, so why not pay someone else to deal with the paperwork and bother? All FB certs are on the CT logs as a matter of policy, so that there are no loopholes in our current statement that if a Facebook cert is not on the CT logs you should not consider it valid; we will accept the loss of secrecy (and people launching new stuff hate it but have learned to adjust) if the end result is making it harder for someone to slide a dodgy cert into the chain.
- fblp 11y agoI'm surprised by the amount of certificate fragmentation these companies have. Why would they use so many different certificate types and vendors? Twitter is even worse: https://crt.sh/?q=%25.twitter.com https://crt.sh/?q=%25.twitter.com
- sandGorgon 11y agoBTW - Anand is a security engineer working for Flipkart and is one if India's smartest security experts. This is not the first time he has found bugs. http://yourstory.com/2015/10/techie-tuesdays-anand-prakash/ http://yourstory.com/2015/10/techie-tuesdays-anand-prakash/
- deleted 11y ago[deleted]
- annnnd 11y agoI would love to know if someone has exploited this bug - should be fairly easy to learn that from logs (this attack is far from stealthy). I guess FB will never tell. :)
- s3arch 11y agoFor these individual hardworking security analysts, Facebook awarding cash prices of "any real value" is much worth than some news article reporting it as "...simple security flaw...". http://www.zdnet.com/article/facebook-fixes-simple-security-flaw-which-let-you-take-over-any-account/ http://www.zdnet.com/article/facebook-fixes-simple-security-...
- moonshinefe 11y agoA whole $15k? This could have cost them hundreds of thousands if not millions in lawsuits. That's a pretty crappy incentive, I'd imagine a lot less moral security researchers getting exponentially more money out of something like this by just selling the 0day. I wonder why the reward is so low. This is literally the amount a code monkey gets paid after 3-5 months of work with minimal skills.
- adam12 11y agoAnyone else have trouble with that webpage? It froze my browser (Chrome).