8 ms·
Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall
- pella 13y agohttps://news.ycombinator.com/item?id=6229858 https://news.ycombinator.com/item?id=6229858
- ArabGeek 13y agoHe did that after facebook security team rejected his request to report a bug
- DangerousPie 13y agoTo be fair they rejected it because his "report" consisted of a link to a profile where he claimed to have exploited the bug, without any explanation of what he actually did. If he had at least given a rough indication of what the exploit was I am sure they would have reacted differently.
- ArabGeek 13y ago"----Original Message to Facebook----- From: kha@hotmail.com To: Subject: post to facebook users wall . Name: Ḱhalil E-Mail: khal@hotmail.com Type: privacy Scope: www Description: dear facebook team . my name is khalil shreateh. i finished school with B.A degree in Infromation Systems . i would like to report a bug in your main site (www.facebook.com) which i discovered it . repro: the bug allow facebook users to share links to other facebook users , i tested it on sarah.goodin wall and i got success post link - > https://www.facebook.com/10151857333098885 https://www.facebook.com/10151857333098885 -----End Original Message to Facebook----- "
- DangerousPie 13y agoYour point being? He doesn't explain the exploit at all, he just gives them a link to some profile he claims to have exploited (which already violated their ToS).
- iso-8859-1 13y agoNo wonder they ignored the bug report. It looks like a spam e-mail. Why no proper capitalization? Why is your education relevant?
- neotek 13y agoEnglish isn't his first language.
- borplk 13y agoThat doesn't automatically make it ok for him to go ahead and exploit someone's profile for attention (for the 2nd time). He wrote a lazy report and knew they did not understand him. He could write a more detailed report and tell them that they have misunderstood him. Or he could write one in Arabic and ask them to get help from one of the Arabic-speaking employees. After two messages back and forth, he says "i have no choice other than report this to mark himself". He did indeed have many other choices but he jumped straight to posting on Mark's profile which he knew will create a global shit-storm. It's clear he wasn't very reluctant to posting on Mark's profile anyway. He was just waiting for them to ignore him so he can drop his "i have no other choice" line and go ahead.
- tobykier 13y agowtf. We're not going to pay you because after we ignored you you went over our heads.
- ArabGeek 13y ago"of course they didn't use their authority to view sarah’s privacy posts as Sarah share her timeline posts with her friends only."
- jonson 13y agoIn my opinion..I think they should compensate him.They said he violated their terms...Their terms on the whitehat page is not even localised for other Languages. Too Bad.
- mike-cardwell 13y agoIn his first message, he demonstrates that his bug exists by showing that he exploited somebody elses account. This is obviously, never the way to make a bug report. Heck, it's probably even illegal. You shouldn't need to read a sites terms and conditions to know that doing this will be breaking them. It's an expensive lesson. Hopefully it will lead to him being more sensible in future. I have no sympathy.
- orf 13y agoHe also gave no technical information at all. He gave more info on his education than the bug he found.
- 1337biz 13y agoIt's a cultural thing. This should signal most likely some form of competency and credibility upfront.
- pampa 13y agoDenying bounty to a hacker on some bullshit "Terms of Service" violation excuse defeats the whole purpose of the bounty program. Next time a hacker will just sell the exploit to somebody else, cash upfront, and wont bother reporting.
- dylangs1030 13y agoIt's not "bullshit Terms of Service" - Facebook clearly lays out the terms of the Whitehat program. There was no bait and switch - it's very explicitly stated that he should not be exploiting the vulnerability, and that it needs to be clearly explained. I respect that he found a vulnerability, but he still needs to adhere to a website's terms and conditions. If the security team he reports a bug to doesn't "get it" the first time he should try again, not publicize it on Hacker News and attract negative publicity by putting it on Mark Zuckerberg's wall.
- antijihad 13y agoNot that my comment is related to this post specifically, but I just want to clarify something. ArabCrunch (which founder's ArabGeek on HN) is known for his super weird conspiracy theory views on everything, including that he's being targeted specifically, check this: http://is.gd/0BxLrc http://is.gd/0BxLrc and http://is.gd/zXroDO http://is.gd/zXroDO. Also, he uses his website as a tool to link to jihadi websites promoting violence against non-moslems. Check his post congratulating moslems this passing Ramadan [on the arabic version of the site]: http://is.gd/tT5xTb http://is.gd/tT5xTb (the link in question is the first one and it's called منبر التوحيد والجهاد which translates to "Tawhid and Jihad platform". And yes, this is not my account. I created it specifically to post this.
- chiefalchemist 13y agoRe: "We are unfortunately not able to pay you for this vulnerability because your actions violated our Terms of Service." Poor Zuck, literally poor poor Zuck. #Sarcasm Prediction: People will start finding holes, shorting the stock, exploiting the holes, then going public with the exploit and making their money once the stock dips. Done correctly, that probably pays pretty damn well, yes?
- yolajengoo 13y agoUh, no. How many security exploits do you think would impact Facebook's stock? This one? Investors do not care about minor bugs that are fixed quickly.
- tlarkworthy 13y agoThis bug is a spammers paradise though, free advertising by posting on other people walls about products. Gold
- jedbrown 13y agoSimultaneously use the exploit on many investors' FB pages, perhaps starting with their children and families. Nobody cares about an exploit used on Zuck's wall and fixed soon after, but the perception would change if it was more personal and widespread.
- adventured 13y agoThat would work great, in a James Bond movie.
- unreal37 13y agoNo, not really. You need to risk a lot of capital to make any money at all. For instance, to make even $10,000 on a 5% drop in Facebook stock, you would need to sell short $200,000 in Facebook stock and would need to have $100,000 in cash deposited with a broker (initial margin). If the stock goes up by even a penny, you would need additional margin to cover that. A young hacker with no money cannot make any by shorting stocks.
- khalilshr 13y agoi cant reply to all of these comments , but i can say that i love facebook security team when they ignored me ;) thank you for your support . regards .
- thephiga 13y agoso did you get paid?
- vadivlkumar 13y agoDon't worry about your English, just continue to do what you are doing. But understand one thing, what you are doing is only worth to learn one or two. If FB is paying you are not is not really matters! I was little irritated your English was criticized heavily! And it's more irritating when a security team misses to understand a security issue when I was able to understand
- deleted 13y ago[deleted]
- borplk 13y agoI applaud him for his expertise and finding the bug but here are some points Ḱhalil: - You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that. - I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken the time to clearly explain the steps. For example you have said "mark profile" instead of "Mark Zuckerberg's profile". That's just ambiguous language and confuses the reader. They probably receive a lot of wrong reports every day so if you make mistakes like that you are less likely to be taken seriously. - After they said it is not a bug, it is clear that they have misunderstood you because you failed to communicate clearly. You could write a more detailed report and tell them that they have misunderstood you. If not you could report in your first language and let them ask one of their Arabic-speaking employees. - You violated the terms again by exploiting the bug on Mark's profile. It would be bad if it was any other Facebook user too. But you went straight for Mark which will obviously generate a lot of buzz and negative publicity and I'm sure he doesn't appreciate someone randomly posting something on his wall. - Just because they fail to receive your bug report does not make it ok for you to go ahead and exploit it. By exploiting the bug you had found twice you lose your whitehat status and you no longer deserve the bounty. Whitehat does not mean "white hat unless you fail to take my report then I will have to exploit your CEO's profile for the world to see". If Facebook does pay you for the bug, it is just setting a bad example and will be encouraging similar behaviour. After that, every other person who finds a bug too will do something funny to Mark's profile for attention.
- s_q_b 13y agoThe author clearly has a language barrier. Not all bug reports are going to come with sterling reports to back them. In the end, Ḱhalil fell back on the lingua franca of the internet: a working demonstration. The onus is on the organization, not the bug reporter, to vet the information. From what I see, there was more than enough in the report to conclude there was a problem, and follow up. If Facebook security fails in coding the application, in QR, and when a user files a bug report, it is awfully hard to place the blame with the bug reporter.
- thezach 13y agoI made a facebook security vulnerbility report Friday afternoon and have recieved absolutley no response from them.... its getting rather disgusting
- dylangs1030 13y agoGive them a few days? Companies like Microsoft receive 200,000 bug reports each day, and each one has to be examined to determine authenticity. Plus, you sent it before the weekend. It's not "disgusting"...you just need to be patient.
- jliptzin 13y agoJoin the club...I've never received a response from them about basic issues. Now I am a Facebook advertiser with a $30k monthly budget...I thought surely then I'd get some responses from them (for example, when I was unable to make changes to my ad campaign, including daily budget, for WEEKS, due to a javascript bug), but still left completely in the dark.
- coolsunglasses 13y agoThey're partying/sleeping.
- ryandrake 13y agoIf the Facebook security team responded more thoughtfully, we wouldn't even be reading about this as news. Instead of: "This is not a bug" (essentially, "go away") ...they could have said: "Thanks for the report. It seems that English may not be your first language, so to be very clear, in order to check this issue, we will need these pieces of information (A, B, C). Please feel free to reply in your language, and we will have a native speaker help translate." If I was the researcher, the callous "go away" response would have convinced me that it would be more fruitful to sell the exploit to a spammer (who would pay HANDSOMELY to be able to post to anyone's wall).
- ronaldx 13y agoI agree with your point but I disagree with your method. I agree that they should also offer a means to communicate in other languages, if they have that capacity. But, your choice of sentence structure - with clauses and formal social graces - would be hugely more difficult for a non-native speaker to parse correctly. If the goal is to communicate with a non-native speaker, Facebook's message is appropriate for its clarity. Bear in mind also that they probably do want incorrect bug reports to "go away" - unless Facebook apply infinite resources to this, some false negative errors are inevitable.
- dylangs1030 13y ago1. I agree, Facebook probably could have been more tactful in their reply. Your example reply looks good. 2. That said...if you were the security researcher, and you received a "This is not a bug." - you would still be fully wrong in selling the exploit to the highest bidder. It's not ethical to do that just because you failed to get a bounty after reporting it, especially if you only tried once. I think both sides should have done things differently. Hacker News is skewed towards BigCo hatred as a whole, and I think it's showing a bit. The majority is siding with Khalil despite the fact that there are valid reasons for him to not receive a bug bounty.
- ryandrake 13y agoOh, and just to clarify, I'm not coming at this from the perspective of "BigCo hatred". It is in Facebook's best interests to treat white hat reported security issues seriously, even if they don't initially understand them. What are the chances that this security researcher ever reports another bug to Facebook, given how he was treated? Selling future exploits to spammers wouldn't be the ethical thing to do, but if I know "Emrakul" in Facebook Security is just going to tell me to F-off, I start to justify it.....
- tcbrfla 13y agoThere are no excuses. Facebook should expect that hackers with english as a second language (or not even that) will find bugs in the system and that they will not be able to communicate the way the Facebook team expects. They should stop finding excuses and start to focus their efforts on making sure that people with no communication skills can report any bug. Suggestion: Facebook could create a new "Facebook_security" system, which can be used to report bugs. The system would have the same production version, but the terms and conditions would be flexible. It would be used only for security purposes, and if someone finds a bug, they could record the exploit and send to the facebook team. By doing this, they would make sure that any type of bug could be reported.
- ferdo 13y agoFacebook should give him a job. The current security team appears to need some help.