20 ms·
I Hacked into Facebook's Legal Department Admin Panel
- polishdude20 6y agoWhat is this fuzzing tool you use to get the endpoints?
- tptacek 6y agoIt's sort of implied that it's not Burp Intruder, but Burp Intruder would be a pretty normal way to do this.
- deleted 6y ago[deleted]
- mrleiter 6y agoIt's actually Burpsuite, you can tell from the screenshot he provided.
- tptacek 6y agoHe's using Burp Suite for things, but writes about "fuzzing" for directories as if he's not using Burp for that (the plural on "tools" sort of suggests he's using something like dirbuster).
- OminousWeapons 6y agoDirbuster, gobuster, or some variant is probably what was used here.
- LeCow 6y agoBrute forcing is not fuzzing, neither of those are fuzzing tools
- polishdude20 6y agoYeah that's what I thought. Fuzzing doesn't discover API endpoints
- trav4225 6y agoI've always wondered, aren't these types of bug investigations illegal? Aren't the investigators concerned about criminal prosecution? Not being snarky; I'm asking sincerely.
- heavyset_go 6y agoIn the US, yes. Unauthorized access and computer trespass is often felonious. People have gone to prison for logging into an email account by guessing the password.
- snazz 6y agoFacebook allows people hunting for bugs to find them on approved subdomains following their bug bounty policy.
- detaro 6y agoPlaces with a bug bounty program typically publicly state rules for what they think is ok for a researcher to do, specifically to avoid that problem. Without permission like that, yes, such an investigation can quickly move into legally dangerous areas, and not all companies have gotten the idea that if someone is willing to tell you about a problem you want them on your side, threatening or suing them just means the next time someone finds something you're not told. (of course that's not a free-for-all for researchers, if you start actually poking in private data or hack actual peoples accounts that's a problem)
- deleted 6y ago[deleted]
- KMnO4 6y agoGenerally companies prefer if you find bugs and disclose them before malicious parties find and exploit them. Most websites have a “responsible disclosure” policy. If you can’t find this linked on their main page, you can often find it at /security.txt or /.well-known/security.txt [0]: https://securitytxt.org/ https://securitytxt.org/ [1]: https://facebook.com/security.txt https://facebook.com/security.txt
- 6y ago
- lqet 6y agoInteresting, but missing words and strange/missing punctuation make this a bit hard to read.
- ForHackernews 6y ago$7500? Why are these bug bounties so piddling? How much would an exploit like this be worth on the black market? What's the potential loss / liability on Facebook's side? Hundreds of thousands? Millions?
- tptacek 6y agoThere is no market for bugs like these.
- saltyshake 6y agonot even for nation states/APTs? Are you sure about that?
- _tk_ 6y agoI can’t speak for Thomas- but generally you’d want to invest your money in a vuln that is rather static. Web applications with attack surfaces that are constantly changing are not a good fit for a sophisticated attack with potentially huge blowback.
- dennisy 6y agoCould you please elaborate?
- tptacek 6y agoSorry, I didn't write clearly. What I meant was, there is no market for RCEs in random Facebook backoffice sites.
- VWWHFSfQ 6y agoWhere are you going to go to sell it? are you going to go find some tor hidden service with a forum that you can post your exploit on and hope that somebody will give you some bitcoins for it? You think that those are not under heavy surveillance already? The "black market" for this kind of thing is way overblown. And if you think you can just go sell it to some nation state, think again. That's an easy way to end up in a federal supermax.
- Dumble 6y agoI find the paragraph where the author described the exploit hard to read. Basically, he triggered the "Password Reset" process and then guessed the reset token?
- vasuki 6y ago> I sent random requests using intruder with a CSRF token and random emails with a new password to this endpoint /savepassword So this endpoint simply allowed setting up a new password with a POST request for the specified email address and he was able to guess the email .. ¯\_(ツ)_/¯
- zaroth 6y agoThat’s how I read it as well, almost too absurd to believe. SetPassword and the parameters to the function are just username and newPassword. I guess they assumed there was authentication happening before the request would even be served (pre-existing session).
- loa_in_ 6y agoA good example of how security by obscurity can fail. Just because there's no url to an endpoint exposed doesn't mean it shouldn't be hardened
- judge2020 6y agoI think they assumed it was already hardened by requiring authentication, but didn't do any testing (or were unaware of this endpoint being a thing in the software they use).
- deleted 6y ago[deleted]
- iso8859-1 6y agoFirst pentester I found with 12k followers on Instagram: https://www.instagram.com/al_shwele/ https://www.instagram.com/al_shwele/ but 8 on GitHub: https://github.com/Alaa-abdulridha https://github.com/Alaa-abdulridha Instagram keeps surprising me...
- Traubenfuchs 6y agoThe majority of the accounts following him have 0 posts, very low amount of followers and follow thousands of other people. They are most likely bought or collected via an online bot tool. Further quantitative evidence: His posts have a very low amount of likes and comments.
- pletsch 6y ago61 likes off 13k followers..yeah, that's a tough sell.
- Debug_Overload 6y ago> The majority of the accounts following him have 0 posts, very low amount of followers and follow thousands of other people. There's also the issue of "follower farmers". Basically, some spam accounts start following tens of thousands of people hoping at least some will check their profiles, maybe follow them back or click on their spam. I noticed this mostly on Twitter, and after some digging, it turns out to be a common tactic used by spammer bots (or umm, "marketting teams"). I don't know how common that issue is on Instagram though but it could be same.
- deleted 6y ago[deleted]
- baby 6y agoI see this often on twitter. Some account with dozens of thousands of followers, if not more, and very little reaction to their tweet (less than 10 per tweet). It’s obvious to the trained eyes that they just bought followers. I can’t be mad honestly, it’s pretty cheap to signal that you’re a big deal by doing this.
- z3t4 6y agoJudging my the response letter it seems they think he only managed to reset a password... not setting the password. Will be interesting to read the follow up.
- hh3k0 6y ago> Judging my the response letter it seems they think he only managed to reset a password That wouldn't really make sense, would it? As it allowed him to log in. > So let’s get back to see what I’ve done here, I sent random requests using intruder with a CSRF token and random emails with a new password to this endpoint /savepassword > Now I went to the login page and I put the login email and the new password and BOOM I logged in Successfully into the application and I can enter the admin panel
- atum47 6y agowell, I wasn't gonna to comment about this subject, but here we go: I find this value ($7,500.00) kind of low for a discovery like this. The other day, someone shared a link to an app [1] that estimastes how much a only fan user makes. I got tell, it got to me. I was never money orientated and I don't plan to become; but seeing how much someone makes by being naked in front of a web cam vs a software engineer salary is kinda sad. some of the only fans users makes in a month what a plain SE would make in a year. besides the fact that there are some serious wrong thing with the world, I thought this kind of skill would be more rewarded. Giving the fact that you could exploit this vulnerability to make a lot more money (or am I mistaken?). 1 - https://news.ycombinator.com/item?id=25393191 https://news.ycombinator.com/item?id=25393191
- Latty 6y agoDescribing that work as "being naked in front of a webcam" is like calling software development "typing at a computer". You can make any job sounds trivial and downplay its value by describing it in a way that removes the skill and effort involved. I'm not sure why you feel the need to imply some else's work isn't valuable to make the point that this work should be more valuable.
- throwitaway1235 6y agoYou brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
- sltEvas 6y ago2%? You have an interesting idea of the world's population. Just think about what that means. It means 2 out of 100 people can hack into Facebook's Legal Department Admin Panel. I mean if we are talking "mentally capable to achieve that within a decade if the person does nothing else but strive to that goal"... Perhaps. If we are talking "sit down right now and do it", then it's more like what... 10,000-100,000 people on earth? Which makes for more like 0.0014%?
- jiofih 6y agoSo logically you deserve to be paid 0.0014% of Facebook’s yearly revenue, which is around $1,176,000.00! /s
- throwitaway1235 6y agoWas a wild guess. I'm not a software engineer. More like a Stewart Cheifet lol. But thank you, very interesting.
- neffy 6y agoNot quite. The US alone graduates 2 million Computer Science students of various stripes every year. It's been graduating (smaller numbers) of them for over 40-50 years now. There are now second and third generation comp sci. workers and graduates. So let's say 1% of 1 million/year are up to this, I suspect it's rather more, but I can't be bothered to do the curve on past graduation rates, and figure out what the world wide figure is... you've easily got a couple of million people world wide. When I think it's going to get really interesting is in another 10 years or so when there start to be significant numbers of bored retired former developers. At any rate the market rate probably isn't that bad.
- dang 6y agoUrl changed from https://alaa0x2.medium.com/how-i-hacked-facebook-part-one-282bbb125a5d https://alaa0x2.medium.com/how-i-hacked-facebook-part-one-28..., which points to this.
- anonu 6y ago$7500 seems low for this bug. If I were Facebook i would raise it. Why? Cost/benefit analysis tells me I could probably get a lot more for this bug going to some more nefarious actors. $7500 is a drop in the ocean for a company like FB who has a reputation to keep intact.
- zitterbewegung 6y agoHow do you know if this is happening or not?
- underwater 6y agoIf you're OK commiting blatantly illegal acts for money you could just go rob a bank, too.
- LockAndLol 6y agoCan someone name this fallacy for me? It sounds like the slippery slope fallacy, but I'm not sure.
- underwater 6y agoMaybe you're thinking false equivalence? What I'm pointing out that just because you can make a lot of money by doing something illegally doesn't mean you should expect to similar amounts of money using those skills in a legal way. Walter White would back me up on this.
- kart23 6y agoIts a strawman.
- ss2003 6y agoLots of places you could do this from where it would not be illegal.
- TameAntelope 6y agoIt’s at least marginally harder to get shot sitting at my laptop in my room...
- petters 6y agoHow on Earth did this endpoint pass code review at Facebook? The person who wrote it probably was working under the assumption that the calling user was logged in, but still....
- underwater 6y agoIt's undoubtably some third party system, not code written at Facebook.
- np_tedious 6y agohttps://legal.tapprd.thefacebook.com/ https://legal.tapprd.thefacebook.com/ You're probably right. Windows Server / IIS doesn't seem like them
- petters 6y agoThanks, this seems likely.
- dboreham 6y agoYou have an unrealistically high expectation of code review.
- anonytrary 6y agoEveryone has an unreasonably high expectation of engineer quality at FANG.
- petters 6y agoI have worked several years at FAANG, and error like this were very hard to make due to how the frameworks were written. But it seems that this was third-party code, which I guess explains it.
- forgot_old_user 6y agoI think it depends on team dynamics. On a team I was on (Fortune 100 company), a techlead would just buddy up with a very junior one, and have them rubber stamp their code review. The techlead almost committed a bug similar to one in this post- I had to step in and leave a review comment to prevent this vulnerability. I almost wanted to have it shipped to get back at at these code review buddies, but decided against it as I valued not having a vulnerability more.
- etxm 6y agoFacebook had better up that payout on the other two vulnerabilities he found.
- zz_throwaway_zz 6y agoHow is this possible? Even in my 1 weekend web apps I ensure password reset tokens are secured against their user and token type, but Facebook, a $720,000,000,000 company, can't do it for their ADMIN site?
- baby 6y agoThere’s fundamentally no difference between a large corp with thousands of employees (who can either use best practice and the secure rails given to them or go wild in their implementations) and a one person company.
- greatgib 6y agoI'm a little bit disappointed, because from the title I expected a little bit of deep dive into the content of the admin panel. Something like an insight into what kind of secret power or privacy abuse was available to the legal department without the users really realizing.
- tptacek 6y agoExploiting a vulnerability to learn and then reveal trade secrets is probably a crime. You have Facebook's tacit permission to look for vulnerabilities, but not to use them or pivot from them.
- greatgib 6y agoIt is not trade secret. It would be in the public interest. Just let me remember you that we are speaking about Facebook and user's privacy... As we have discovered through recent scandals, a lot of people are not aware of the level of abuse on their privacy they expose themselves by using Facebook. But just reusing the devil's argument, if they have nothing bad to hide, there is no issue to be transparent...
- tptacek 6y agoThat's not how that works at all. You absolutely do not have a right to hack into private companies "in the public interest".
- webmaven 6y ago> That's not how that works at all. You absolutely do not have a right to hack into private companies "in the public interest". Well, not as a private individual, certainly. You have to work for a nation-state's Advanced Persistent Threat group like the NSA's Tailored Access Operations.
- megous 6y agoParent comment is not talking about "rights", just public interest.
- rdtwo 6y agoWith that kind of skill you should just be working website and buying PlayStations, shoes and other high demand goods in bulk. You can make moths than 7k per week
- thatwasunusual 6y agoWhat a life!
- rukshn 6y agoAwesome post. Shameless plug on a similar exploit I found using the browser developer tools on a large scale application https://github.com/rukshn/rukshn.github.io/blob/master/archives/easter/egg.md https://github.com/rukshn/rukshn.github.io/blob/master/archi...
- wut42 6y agoInteresting post, but I have troubles understanding the "SSL vulnerability with the exposed IP address" part. SSL does not prevent knowing IP addresses...
- BenjiWiebe 6y agoAnd from the screenshot, that's just DNS resolution. Nothing to do with SSL.
- mherdeg 6y agoIt's kinda cool that because this webapp is evidently so little used in public, if you just do a Web search for "facebook tapprd" you're pretty much just gonna find bug bounty writeups ( e.g. https://medium.com/@amineaboud/story-of-a-weird-vulnerability-i-found-on-facebook-fc0875eb5125 https://medium.com/@amineaboud/story-of-a-weird-vulnerabilit... ).
- fareesh 6y agoSo in this case he actually changed someone's password - don't they have a policy saying that you have to only do this kind of stuff with your own account or in a sandbox? Or is this exempt because such a thing is not possible since it's internal?
- ttsda 6y agoThe way the admin panel screenshot is censored is not good as per this post: https://news.ycombinator.com/item?id=25326450 https://news.ycombinator.com/item?id=25326450 All those names could be recovered in theory.
- devpbrilius 6y agoProofreading services.