8 ms·
Facebook exploit – Confirm website visitor identities
- what_a_joke 8y ago$1,000? That's like six figure lawsuits right there, for a bug like that.
- supernovae 8y agoIs there something in here we're missing? Someone finds exploit, gets the bounty, facebook fixes and we have a timeline. Sounds like the system worked... are we looking for something else here?
- abhisuri97 8y agoI don't think there's much to see here...it is a cool bug though that doesn't require a super high level understanding of security to figure out. But a 6-9 month time to fix seems really long (also I would have thought a $1000 bug bounty is low for this type of exploit...but then again I'm not in this space too much to know the average rewards).
- DanFeldman 8y agoBeing charitable here, it may be that this exploit showed a breakage in their internal API security process, or an edge case previously unhandled. Perhaps FB had to run an internal audit to find any other endpoints effected by this bug. Buggy endpoints then need to get fixed, tickets get sent out, but with a low priority because this is a low priority bug, and voilà, 6-9 months.
- abeyer 8y agoOne could also question whether they used the lure of a bounty to keep someone quiet while they let customers (aka advertisers) continue to benefit for an extra 9 months at the expense of the users. I guess you'd have to consider Facebook's track record in terms of how charitable vs. cynical you want to be in interpreting their actions.
- baroffoos 8y agoCouldn't facebook just provide some secret service for identifying users behind the scenes that regular devs can not access?
- jcims 8y agoThe thing to also keep in mind is that the bug bounty teams are typically centralized and not embedded within the product teams of the services being reported on. They certainly get prioritized attention, but there are still layers of communication to report the issue, follow up with devs or reporter if there are questions or difficulties reproducing the issue, prioritize the issue, fix the bug and deploy to prod. Not to say that’s the way it is at Facebook, just what I’ve seen in the past.
- userxyz135 8y agoIt's common in the bug bounty community to write about how you found the bug and how the reporting process went.
- dpwm 8y ago> are we looking for something else here? No. But some people, myself included, are interested in this sort of thing. It's also interesting to see the timescales of the fix. Posts like this demonstrate that the system worked, albeit perhaps a bit slower than we'd like to imagine. Whilst the reports of bug hunting apparently within the scope of the bug bounty resulting in a legal team responding with a false dichotomy between an NDA or prosecution are particularly juicy, it's also nice to hear about the cases where that isn't the outcome.
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- paxys 8y agoWho is complaining about anything? It's a nice article about a neat little exploit, and the process to find it.
- patorjk 8y agoI found an exploit like this in Google+ back in 2013 that worked in basically the same fashion (script tag and onload/onerror handlers) to identify users, and to tell if they were apart of certain groups. Google fixed the issue, but later wrote back: > The panel has determined your report did not meet the threshold for a reward or credit in our Hall of Fame. Thank you for reporting this issue and good luck with your continued bug hunting. That always kind of rubbed me the wrong way. I found a similar bug in Facebook [1], though it used image size instead of the script tag. Like the OP, I was given $1000. It definitely made me feel a lot more favorable towards Facebook's security team. [1] http://patorjk.com/blog/2013/03/01/facebook-user-identification-bug/ http://patorjk.com/blog/2013/03/01/facebook-user-identificat...
- eveningcoffee 8y agoHow much did Google offer for a security bug (if they would have accepted it)?
- tptacek 8y agoIt very much depends on the bug.
- chipperyman573 8y agoA bug by the same author (referenced in the article) that allowed anyone to undetectably upload a sitemap to any other person's website (and appear at the top of search results by claiming to be associated with the website) only got $5000, when it could have easily been sold for tens of thousands to blackhat SEO companies. So the answer is probably "way less than street value but still nonzero" http://www.tomanthony.co.uk/blog/google-xml-sitemap-auth-bypass-black-hat-seo-bug-bounty/ http://www.tomanthony.co.uk/blog/google-xml-sitemap-auth-byp...
- tptacek 8y agoThat's a really good bug! But $5k sounds pretty reasonable, since the only alternative market for it comes with pretty obscene legal risk (unlike an RCE, which will have a whole variety of white- and grey- market buyers, an SEO bug seller knows exactly what their buyer is doing with their work).
- saagarjha 8y ago> Because the endpoint is HTTP2 it also means you can have many of these requests in flight at once, which makes checking against large lists of IDs very quick. It's interesting that there wasn't any rate limiting on this API, it seems like?
- notafrog 8y agoNot surprised. Back in 2016 there was a bug in Facebook beta where you could bruteforce the verification code when performing a "forgot password" request. There was no rate limiting...
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- air7 8y agoI once (2009) found a similar bug that allowed leaking the ID and personal info of a FB user when their browser loaded a seemingly innocent <img> tag (so it could be embedded in a forum post, for example). Sadly, it was before FB had a bug bounty program, so I didn't receive anything after I contacted them and they fixed the issue. I wrote about it here: http://blog.quaji.com/2009/07/facebook-personal-info-leak.html http://blog.quaji.com/2009/07/facebook-personal-info-leak.ht...
- Chris_Chambers 8y agoUsing a Facebook exploit for anything less than causing as much damage to Facebook as possible is a sign of severe moral impotence. Siding with Facebook and selling out for their bug bounty bribe is bad enough, but to do it for free deserves some sort of punishment.
- wolco 8y agoIn 2009 they had private photos exploits, login exploits and all other kinds open access issues. Fun times.
- notafrog 8y agoA friend of mine used to have a Facebook page with about 180k fans back in 2008 or 2009. He was so greedy, he found some "javascript code to increase fans" and ended up giving admin rights to the page to some "hackers". Then Facebook started requiring a password to make changes to page administrators, but they never returned the page to him.
- renholder 8y agoDid someone get a grab of it, by any chance? Getting 502 bad gateway from Cloudflare.
- dddddaviddddd 8y agohttps://web.archive.org/web/20190305014509/http://www.tomanthony.co.uk/blog/facebook-bug-confirm-user-identities/ https://web.archive.org/web/20190305014509/http://www.tomant...
- aboutruby 8y agoOne nice thing about GraphQL is that there is only a few endpoints to secure instead of thousands.
- aiiane 8y agoA question worth pondering is if this is something that should continue to be fixed at the site level, or whether it's representative of an overarching problem with the data that browsers make available around cross-origin requests. access-control-allow-origin was supposed to be the means of addressing cross-origin concerns, but in this case even its usage doesn't prevent the issue. Perhaps browsers need to expand the potential effects of access-control-allow-origin.
- cheeaun 8y agoJust wondering, how or what was the fix for this exploit?
- Sebb767 8y agoIn this case, it's probably just prefixing both requests with the protection against embedding and sending the same headers.