7 ms·
Stealing Facebook access_tokens using CSRF in device login flow
- cloudjacker 10y agoso you got paid $5,000 ? How long since the first report did it take for that to reach your bank account?
- franjkovic 10y agoThe bug was reported on December 8th, 2015 and fixed on February 18th, 2016 which is an unusually long time for Facebook. The bounty reached my account during the middle of March, but Facebook has recently changed their bounty payment processor to Bugcrowd, and now they have weekly payments.
- artursapek 10y agoWeekly payments as opposed to a lump sum? Why? I can't imagine cashflow is an issue for them.
- nkozyra 10y agoI took that to mean payments every week instead certain payout times.
- ceejayoz 10y agoI took that as "they payout all bounties due weekly via an automated system instead of whenever accounting gets around to writing a check".
- kornish 10y agoI suspect franjkovic means that there's a queue of lump sums to get deposited to their respective owners, and payments in that queue get processed once per week.
- cmdrfred 10y agoWeekly, as opposed to Google's biannual system.
- deleted 10y ago[deleted]
- daraosn 10y agoI think $5,000 is a joke, this is a serious vulnerability... Despite this, congratulations for finding it and reporting directly to them, the right way. If it's possible to know, how many hours did you spend researching this?
- cmdrfred 10y agoHell, I'd pay 6 just for shits and giggles.
- tptacek 10y agoThen do it. Facebook has a great security team, but it's a huge product with a lot of code churn, and there are plenty of shits and giggles left to find. Hang up a sign on Twitter or here, something credible that you can't get out of simply by changing your name to "admiralfred" or "commodorefred", that says you'll pay $6,000 for a Facebook CSRF. You'll get a taker. Nobody other than Facebook is bidding for these bugs, and you're promising to be the high bidder for a lot of them.
- jfoutz 10y agoHmm. Seems like Facebook should create some front entities and buy cheap exploits on the black market. Of course, perhaps they already do. Smart folks work there. edit Actually, now that i think about it, someone in the right situation could probably make a nice living for a few years buying cheap/obscure exploits for lots of companies that provide bug bounties and submitting them. Beer money at least, perhaps tuition. Seems sort of on the scale of small time drug dealer. Illegal, very risky in the long term, but possible to get away with for a few years if you're cautious.
- rl3 10y ago>I think $5,000 is a joke, this is a serious vulnerability... I tend to agree. They should probably add a zero to that. Obviously $5,000 is a lot of money, but not to Facebook, and especially not in the context of fixing serious vulnerabilities on a platform that has 1.65B users. If Facebook paid more they'd enhance their security in the process, at the cost of what amounts to chump change for them.
- NDT 10y agoPretty cool that FB's first years get $50k+ signing bonuses, but a serious vulnerability gets $5000
- elliotec 10y agoFB's first years only get $50k? In Bay Area California??? WTF world am I living in where people actually get compensated properly? The past few days I've seen posts where compensation at very respectable companies is abysmal! Edit: Apologies for not reading it correctly. I now stand corrected that the parent meant a $50k signing bonus in addition to a more reasonable annual compensation.
- nxzero 10y ago$50-100k signing bonus; not annual compensation.
- awinder 10y ago50K signing bonus
- rrdharan 10y ago$50k signing bonus. The parent poster was sarcastically pointing out that entry level engineers who are likely not contributing much to Facebook's bottom line are compensated way more than the security researchers finding these potentially costly vulnerabilities.
- elliotec 10y agoPhew. Thanks.
- rhizome 10y agoI glossed over the trailing space on the plus sign and read it your way first too, FWIW.
- emmett 10y agoI'm pretty sure a first year security engineer at Facebook gets paid a lot more than $5k too. They're not your employer, they don't owe you money, if you want to mess around looking for security vulnerabilities in your free time it's good of them to pay you at all. I fully support Facebook paying bug bounties, but let's compare apples to apples here.
- evoltix 10y agoOut of curiosity, was there any particular reason why you decided to write a blog post about this vulnerability 5 months after the bug was fixed?
- franjkovic 10y agoI wanted to move from Blogspot to a personal domain, but kept delaying it for a long time.
- deleted 10y ago[deleted]
- dopamean 10y agoThe circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.
- danbolt 10y agoI'd love to learn about how these sorts of vulnerabilities tend to get moneitized in black market settings. Is there much reading available for that kind of thing?
- dopamean 10y agoI don't know much about it tbh. tptacek and a few others have spoken extensively about bug bounties on HN. I'll try and dig up a few of their past comments. Essentially what the argument comes down to is that a one off bug to exploit a company like Facebook is actually not worth very much to anyone on the black market because the bug is likely only valid for one company and that company will likely patch the bug very quickly. This leaves the attacker with a very narrow window to exploit the bug. Attackers on the black market paying for exploits are looking to make money from those exploits. If there is only one place they can use the exploit and perhaps only have a few days or even hours to use it how much would it really be worth? The exploits that pay big on the black market are ones that are enormously widespread and less likely to be fixed quickly. If I can find better, more detailed, explanations I'll post them here. Maybe tptacek can link to his past comments...
- Trundle 10y agoWhat's more is there can't really be an established "market" for a unique exploit. If a product isn't being regularly traded then there's no easily findable pool of buyers. There's also no ongoing/repeat business which outside of contract law (and even for plenty of business conducted under contract) is all there is to keep people honest. You'd need to be very well connected to be able to get good value out of an exploit. There could very well be people that are. Hackers in leather dusters travelling the world exchanging thumb drives in shady third world bars, sounds cool as hell, in fact I hope there are people living that life just because it makes reality that little bit more interesting. But your average pen tester isn't that. Whenever i see the "better value on the black market" crowd show up here I'm actually reminded of a, Jim Jefferies I think, bit about the black market not meaning you can just head down to the docks at night going "GUNS. I WANT TO BUY A GUN".
- spoown 10y agoWell done, i hope you made some €€€ on it...
- a_imho 10y agoThe black market is a false dichotomy. Either you need the money for your work, then negotiate a reasonable price, or you don't, then disclosing it for free might actually helps someone not to be lowballed by BigCo the next time. There really should be a bug marketplace, instead of one side having all the power and paying pennies.
- tptacek 10y agoMarkets aren't magical. They route resources, they don't create them from thin air. If Facebook is ultimately the only organization that realizes $5000+ in value from a vulnerability, then no matter how you structure the marketplace, it isn't going discover a higher price for that flaw. If you believe otherwise, you're missing a business opportunity. Go create a "bug market" for Facebook and Google serversides. It's not illegal to buy vulnerabilities, or to sell them (so long as you're reasonably sure they're not going to be used as part of a specific criminal enterprise --- but don't worry, if you stick a $5000 price tag on a serverside bug, or even a $500 price tag, you can be pretty sure it won't be used by criminals).
- a_imho 10y agoBy submitting a bug through a bug bounty system you place the reward into Facebook's hands. Following the same argument you can say they can offer $1, because they are the only organization interested in the bug. After all exploiting a vulnerability puts you on the wrong side of the law. However I do believe saying you discovered a pretty serious bug by putting it on a market sends a strong message. Your system is vulnerable and you are too cheap to pay up.