13 ms·
How I Hacked Facebook and Found Someone's Backdoor Script
- ayben 10y agoemreayben23
- deleted 10y ago[deleted]
- 6stringmerc 10y agoArticle is exactly as headline advertised, and a well-laid out write-up. Neat to come across it.
- sveiss 10y agoThis isn't the first time files.fb.com has been publicly reported as having been breached: http://www.nirgoldshlager.com/2013/01/how-i-hacked-facebook-employees-secure.html http://www.nirgoldshlager.com/2013/01/how-i-hacked-facebook-... .
- coldcode 10y agoFascinating. Looking for a hackable system and finding someone beat you to it.
- bediger4000 10y agoThe author and Facebook, Inc are lucky that the earlier hacker was just a regular spam criminal, not some bigtime "Nation-State Hacker". The Nation-State Hacker probably would have been a great deal more careful and not left easy-to-spot PHP backdoors lying around. This also points out a weak area in our knowledge of hacking - how often does a given exploit get rediscovered? This and other anecdotes show that it happens at least once in a while. Prevalence of rediscovery could put lie to the NSA's "NOBUS" assumption, though. So we're likely to never see the results of such research.
- morley 10y agoThis is a great write-up. I know little about pen testing, yet I was able to follow along easily.
- TheGuyWhoCodes 10y agoNice work, very detailed. However this is hack of Accellion’s Secure File Transfer. How should Facebook, or anyone for that matter, protect themselves in these cases? I mean other then some obvious ones like not running as root, limiting file access, limiting network access to other servers...
- chromakode 10y agoReason about the software as if it has already been compromised. Think about how user credentials and private keys the server touches can be used to attack other internal services, and try to limit the scope as much as possible.
- chatmasta 10y agoIt's buried in the bottom of the post, but I'm happy to see that Facebook paid a bug bounty of $10,000 for this. In the past we've seen Facebook refuse to pay bug bounties when the hacker goes beyond scope. Interesting that going beyond the usually scope of bug bounties actually discovered a latent exploit and helped Facebook. Maybe this will result in change of policies for bounty scope.
- gillm4 10y agoI know nothing about pen testing, but this was very interesting and easy to follow regardless. Thanks so much for sharing!
- volkk 10y agoI really think 10,000 for serious exploits like these is just not enough money. Even if OP only spent an hour or two on finding this out (although highly unlikely), they should pay based on seriousness/potential damage of the bug. Great writeup though. Super interesting stuff.
- zodPod 10y agoSeriously! Especially for a company as big as facebook!
- dev1n 10y agocommon response to why companies don't pay a ton of money for these exploits [1] [1]: https://news.ycombinator.com/item?id=11249173 https://news.ycombinator.com/item?id=11249173
- nickpsecurity 10y ago"Say they buy it for $20,000. Do you really think someone will derive $20,000 of profit from this before it's caught and patched by Facebook? The only vulnerability worth $15,000 or more is one directly impacting a language, a widely used development library/framework or a widely used piece of software." I think that statement might apply here given the FTA issues. Hackers could've gotten plenty mileage out of it. Especially if others at Facebook, like their AI team, used it for something that's a trade secret. That's speculation but it's not like hacking a news feed.
- EthanHeilman 10y agoIts not just the value to the finder but the cost to facebook. Generally the profit an attacker makes is an order of magnitude less than the cost they incur.
- nickpsecurity 10y agoGood point. That should be factored in.
- nickpsecurity 10y agoNice write up. Of course, this would be the team member whose photo is merely an Orange. Paranoid security people haha... Part that jumped out at me, aside from obvious goodies, was this: "FTA is a product which enables secure file transfer, online file sharing and syncing, as well as integration with Single Sign-on mechanisms including AD, LDAP and Kerberos" ...followed by... "...web-based user interfaces were mainly composted of Perl & PHP... PHP source codes were encrypted by IonCube... lots of Perl Daemons in the background" Wow. That inspires a lot of confidence in the "secure" product. I'd have doubted Facebook relied on such a system had I not known they built their empire on PHP. We all know its reputation. Their "secure, file-transfer appliance" fits right in.
- utefan001 10y agoSeems like two factor authentication here would have helped.
- jcoffland 10y agoHow?
- willvarfar 10y agoThey were able to snarf passwords plaintext.
- Torgo 10y agoBecause the backdoor was logging fb developer credentials. The stolen creds would not be useful with two-factor required every time.
- walls 10y agoIf the attacker has control of the box, he can just man-in-the-middle a two-factor token. It would certainly require the attacker to be a little more proactive, but it would hardly stop the credentials from being useful.
- Matt3o12_ 10y agoBut he did not have access to the box with the 2FA. The attack just had access to a box hosting software from a third party, completely isolated from FB's infrastructure. With the passwords, however, he might have gotten access to the VPN or services. 2FA would have certainly helped. This is of course only interesting if the passwords were reused (even the most security minted folks do that). If a third party vendor does not support 2FA, or when dealing with legacy code, it believe it is good practice to only use randomly generated passwords by password managers.
- mxuribe 10y agoQuite clever find! Good write-up, too! Kudos!
- reginaldo 10y agoThis is Reginaldo from the Facebook Security team. We're really glad Orange reported this to us. On this case, the software we were using is third party. As we don't have full control of it, we ran it isolated from the systems that host the data people share on Facebook. We do this precisely to have better security, as chromakode mentioned. After incident response, we determined that the activity Orange detected was in fact from another researcher who participates in our bounty program. Neither of them were able to compromise other parts of our infra-structure so, the way we see it, it's a double win: two competent researchers assessed the system, one of them reported what he found to us and got a good bounty, none of them were able to escalate access.
- ledy 10y agohttps://www.facebook.com/sumyangriani.cieimouetz?fref=ts https://www.facebook.com/sumyangriani.cieimouetz?fref=ts
- omash 10y agoIs what the other researcher did (collecting usernames and passwords) in scope? Is it impossible to use these credentials to get above standard privs on any part of facebook?
- d33 10y agoThis is pretty much why we shouldn't be trusting centralized services at the scale of Facebook. Given that two researchers got that far, sooner or later another will actually manage to escalate the privileges. And then, I'm not sure what we should be more afraid of - leaking it all to public or some three-letter agency using it for nefarious purposes... Seriously, don't do Facebook. Not even once.
- nemothekid 10y agoThis reasoning is really flimsy. Are you suggesting a that a normal user will do better at securing their home grown system than a team of trained security engineers?
- 10y ago
- dopamean 10y agoI'm not sure I understand some of the comments here claiming that 10k is not enough money for this. It clearly is enough money because Orange found the problem and reported it. These arguments always remind me of people claiming that certain professions are not paid enough. They forget that there is a market for labor and in this case the labor is finding vulnerabilities. People will either be willing to work for the posted price or not. In the case of pen testing facebook I'd be willing to bet there are plenty of people out there looking for bugs who aren't even really concerned with what the final payout is going to be. Yeah, they could have gotten completely owned if he didn't report this. But to him reporting it and getting 10k in compensation was sufficient. Why would facebook pay him a million if he was willing to take 10k?
- awakeasleep 10y agoThere is an implicit "without exploitative downward pressure on wages" clause to the sentence every time people say "_______ isn't paid enough" You forget that no assertion of values makes sense when divorced of context.
- interurban 10y agoBecause the pay scale is subjective and the reporter doesn't know the amount before they report. FB and others have guidelines for their bounty programs that leave an upward bound open for severe vulnerabilities. The argument these comments are making is that this report should qualify in some way for a higher payout. I'm not arguing for either side here, just noting that the comments that you refer to are fairly reasonable.
- nickysielicki 10y agoThere are two markets for this type of labor: one provided by the bounty programs and one provided by those who want to abuse the vulnerabilities, eg: secretive three-letter-agencies, etc. I would imagine that the latter of the two is almost always willing to pay more. I would also imagine that by the time you're a skilled pentester, you're in your mid-to-late thirties and maybe are worried about how you're going to put your kids through college, or how you're going to retire. So what do you do? Do you take the larger sum of cash and plague yourself with worrying about bitcoins, how you're going to lie on your taxes, and deal with the ethics of helping shady organizations? Or do you help the company? Now you don't have to lie on your taxes or launder bitcoin, but you do have the pressure to find more security problems to make enough cash to meet your financial needs. And the ball is solely in the court of the companies running bounty programs-- if they were to always provide more money than the black market, there's virtually no reason to bring it to someone else. I don't think it's unreasonable for them to not want to give away more than they have to, but I get the sense that there's little to no negotiating power for the vulnerability finder-- and they should probably work on that.
- lawnchair_larry 10y agoSo since they were unable to pivot laterally, you pat them on the back and call it a win. But last time someone did successfully pivot laterally, you threatened his employer? You guys are really sending mixed messages! Are they allowed to escalate or not? And if that's the new policy, shouldn't you pay the other guy who did escalate?
- mkane848 10y agoThat's kinda disingenuous and you know it. From the previous discussion[0], you should know not to take one side of the story at face value. [0]https://news.ycombinator.com/item?id=10754194 https://news.ycombinator.com/item?id=10754194
- brazzledazzle 10y agoHaving participated in that conversation I can say that the timelines and statements from facebook were suspect. I'm sure the researcher didn't make the best choices but how facebook handled it was horrible and should make anyone participating in that bug bounty carefully consider every action they take against facebook's infrastructure.
- nickpsecurity 10y agoWow. That was an interesting set of comments to read. The consensus of the crowd was actually against Facebook in that probably due to their overpromising on bounties for big compromises and under delivering plus going after dude's job. A number of security professionals, including a friend of Stamos, were against that because he dumped and sat on data plus had his business info involved. Cited expectations of pentesters and responsible disclosure. What a mess. I don't think Wes acted in good faith in that one but neither did Facebook in anything privacy-related. Who cares about fundamental ethics given parties involved. I will say his actions were nearly warranted if Facebook was promising huge bounties for something that could cause them big problems which that case seemed to be from that thread's comments. I don't know for sure. Far as escalation or downloading data, I found that to be the only way to get taken seriously by management. Had to be done non-disruptively with trusted personnel, protection of that data (eg RAMdrives, crypto), and assurance it was gone after. Rarely even read it as filenames & credentials were enough. Nothing like showing marketing plans or private emails to execs with a contract that's vague enough for it to be legal to get security taken seriously. Responsible disclosure debates of 90's showed us that letting vendor decide almost always resulted in them downplaying risk saying it "hypothetically" could do something but probably overstated. People playing that game usually get bounties that yearly add up to less than a median IT person. Rather not play that game. If the company bullshits, do what you can within their legal framework to call them on it and provably without doing any damage. If they didn't in that case, then he went way overboard and looks like he's running an extortion racket. I think key parts of the story aren't published and I can't be sure. Good news is Facebook and Wes both of don't mean shit to me. Moving on. Appreciate the entertainment and different perspectives, though. :)
- ryanlol 10y agoOnly $10000? What the hell do you have to find to qualify for that "million dollar bug"?
- fabulist 10y agoIf you can find a way to use their backup tool to download an arbitrary user's profile, and they don't pay you out at $1M, "BS" can be safely called.
- deleted 10y ago[deleted]
- oliverhands 10y agoi hacked facebook and someone saw me hacking and siad why are you hacking and so that's how i hacked facebook
- libber 10y agoIf there is someone to be upset with in this situation its accellion the vendor who backs files.fb.com. Looking at how egregious their security mistakes are they dont appear to take security seriously. This is the same company that (last I was down there) had a billboard on 101 that says "Secure". Many echos of oracles "unbreakable" ad campaign while being an aggressively bad at security company
- Techbrunch 10y agoThis is the same researcher that found a RCE in Uber: https://hackerone.com/reports/125980 https://hackerone.com/reports/125980 Shameless plug but if you like that kind of articles I suggest signing to my newsletter: http://bugbountyweekly.com http://bugbountyweekly.com. A free, once–weekly e-mail round-up of news and articles about Bug Bounty.
- edem 10y agoWhy do you use so much emoticons in your article?
- frostymarvelous 10y agoSo Wes got only 2.5K after successfully proved he could access signing and api keys,after he was threatened with a lawsuit. How does setting up a shell and collecting credentials and then downloading them later give you a pat on the back? Is this some kind of a joke?