3 ms·
My bad, I didn't read further. I assumed this was server-side. After reading, 4.5k sounds right from Facebook, and while I'd imagine the other market price to
by mischanix 13y ago
My bad, I didn't read further. I assumed this was server-side. After reading, 4.5k sounds right from Facebook, and while I'd imagine the other market price to be higher, I don't think it'd be above 3x, much less 10x, without something special (e.g. high-profile user data) accompanying it.
- tptacek 13y agoIt is serverside (most web app vulnerabilities are). I'm suggesting serversides are worth much less than clientsides.
- mischanix 13y agoWhat I meant is that the user needed to load a flash payload and be logged in properly. The data harvesting happens client-side. The vulnerability itself is server-side, yes, but computers are faster at copying data than engineers are at figuring out what's going wrong. The data you could potentially harvest with an exploit like this, given good planning and enough time to affect a large amount of people, is definitely worth quite a bit of money. This vulnerability could even have helped to make a very convincing phishing attack, which, again, properly executed, leads to very valuable data. It's not remote execution, but I still think it's valuable.