7 ms·
Facebook CSRF leading to full account takeover (fixed)
- RexRollman 13y agoI don't like Facebook but I have to give them credit for addressing this so quickly.
- ryhanson 13y agoHow much did you get for this bug via their bug bounty program?
- objclxt 13y agoGiven the seriousness, I would hope it is in the five figures (Facebook don't go into details about rewards, but a comparable exploit for a Google Account would net you at least $10k).
- deleted 13y ago[deleted]
- pdappollonio 13y agoLet's hope author will update the post with some clues :P
- franjkovic 13y ago12,500$. (More than)Good enough for me, takes a year of work on average salary to get this much money in my country.
- bennyg 13y agoThat's awesome. Congrats to making the money, and raising the issue correctly - as well as not going off of the ethical deep end.
- meowface 13y agoThat's awesome. Also sounds like you should maybe try to move to a different country, if you can!
- brianshaler 13y agoHe'd probably be better off staying where he is and courting customers in the US and UK. The combination of a low cost of living and a metropolitan income (or as close as possible) is a splendid combination.
- adamnemecek 13y agoOut of curiosity, how much time did you spend on this?
- franjkovic 13y agoI spend 4-5 hours a week hunting for bugs. The "session" I found this bug in was around 2 hours long.
- tomschlick 13y agoCongrats. This is exactly how responsible disclosure is supposed to work. You spend valuable time looking for holes and when you find one they fix it quickly and compensate you for your trouble.
- TomAnthony 13y agoWere you able to do this all with the dummy accounts that Facebook provides for the Bug Bounty program or did any steps require a genuine account? Just curious as I always wonder whether there are bugs that affect genuine accounts and not dummy accounts or vice-versa.
- turshija 13y agoSvaka cast druze :)
- foobarqux 13y agoProbably worth $500k to government actor.
- debt 13y agoThat's a pretty amateur mistake for a such an enormous company. Made respect for FB, but c'mon, how'd this slip through? This was a very trivial exploit.
- RKearney 13y agoNearly every exploit is a "pretty amateur mistake" in hindsight.
- adamnemecek 13y agoNot really, no.
- sillysaurus2 13y agoWould you give some examples of some exploits which you feel weren't exploiting amateur mistakes?
- meowface 13y agohttp://www.exploit-db.com/exploits/28974/ http://www.exploit-db.com/exploits/28974/ Here's one. A use-after-free triggered due to some faulty logic. Mistake? Yes. Amateur mistake? No. Even very experienced C/C++ programmers, such as Microsoft's top devs, may accidentally double-free, or use already-free memory.
- himal 13y agoI'm surprised that it took this long to discover this.I wonder how many this type of exploits are still out there.
- bdcravens 13y agoShould the title be updated to reflect that this is 2+ months old? After all, the fix was put in place in a couple of hours. This isn't a current bug, but rather, an excellent post-mortem, but the title suggests present tense.
- adamnemecek 13y agoThe write up is from yesterday about a bug fixed a while back, as per responsible disclosure.
- ParkerK 13y agoMost responsible disclosure is normally posted about sooner though. I think what the OP meant is that waiting 2 months later, and then giving the post this title, makes it seem as though it was a more recent bug
- franjkovic 13y agoActually I waited until we pushed Pyxio website on-line. Since I am not native English speaker, what would be best replacement for current title?
- Miyamoto 13y ago"Post-mortem" is usually appended to titles for solved vulnerabilities, although this was 2 months ago. Maybe just timestamp it? e.g. "Facebook CSRF leading to full account takeover (Post-mortem, August 2013)"
- lambada 13y agoThat would imply that the Post-Mortem itself was written in August 2013, which would probably get far fewer clicks as people assume they've read about the vulnerability before.
- rmc 13y ago
- ryansan 13y agoDid anyone else notice that the site and social networking properties were all put up at the same time as the post (roughly)? Good tactic for starting a business.
- geden 13y agoInterestingly several of my wife's hotmail using Facebook friends accounts appeared to have been owned last night. Has someone found a new similar exploit?
- antr 13y agoI believe so. A friend with a hotmail account (although I don't know if he uses this hotmail account to login to FB) got his FB account hacked couple of days ago.
- chrismarlow9 13y agoThe exploit may not have been patched in the mobile version of facebook or may still work using a hotmail alias (passport.net or w/e). These are just guesses. I dug into Facebook security a while back and they seemed to have very little protection in place on the mobile site.
- franjkovic 13y agoYou can read about all kinds of bugs and "bugs" I found in bounty programs on my old blog, too http://josipfranjkovic.blogspot.com/ http://josipfranjkovic.blogspot.com/
- b0b0b0b 13y agoAre there researchers out there testing whether facebook regresses security fixes? Or would the effort not procure enough reward?
- bonobo 13y agoSomething I don't get, why is a hotmail account a pre-requisite? Wouldn't this work with any other email account?
- franjkovic 13y agoRedirect URL when you give access to Facebook is different for other email providers. Hotmail (that is, Outlook) is the only one that worked as far as I know - I have tested Gmail and yahoo, but neither of them were exploitable (there is also chance I missed something, so it is worth checking again).