7 ms·
Hi. I'm the one who found the bug. Facebook's side of this story is at https://www.facebook.com/BugBounty https://www.facebook.com/BugBounty
by reginaldo 13y ago
Hi. I'm the one who found the bug. Facebook's side of this story is at https://www.facebook.com/BugBounty https://www.facebook.com/BugBounty
- jwcrux 13y agoFantastic bug, and great writeup. Of course, everyone will be curious about the payout ;)
- reginaldo 13y agoWell, it's already disclosed, but I really wanted to know how much people would think this kind of bug is worth.
- onestone 13y agoAfter Ryan McGeehan's comment about the "million dollar bug" (cited in your writeup), I'd say your bug is worth at least $100k.
- jonknee 13y agoA bug that lets you execute code on Facebook's servers is worth millions if not billions of dollars. You'll be rewarded with much less than that, but considering Facebook's market cap it is extraordinarily valuable.
- grugq 13y agoNo, it is not worth "millions or billions". It is worth whatever anyone is willing to pay for it. Since Facebook has very aggressive monitoring and will shutdown hacks quite rapidly, the ROI for a bug like this would have to be realised very quickly. Say in the order of days, (or maybe even hours), rather than months. How would you monetise 1 week of running code on facebook? Injecting malware would get the whole thing shutdown even faster, so you'd have to either go passive or operate in a reduced window of opportunity. There are no legal entities that would buy the bug, the USG can access any data w/ a warrant (thats free) vs. "millions or billions". Any other law enforcement agency could do the same thing. There is really no value there to them. So it would have to be blackhats, and that means some idiotic Russians mass owning everyone with old Java bugs. Again - not worth much. This sort of bug has very little value, except to facebook.
- reginaldo 13y agoI quoted that as a joke. I'm too familiar with bug bounties to ever expect one million dollars as reward for a bug. Let's hope people don't take it seriously. Lesson learned: since I'm not a native speaker, I shouldn't joke unless the joke is obvious.
- famousactress 13y agoComments on the FB post suggest the amount was 33,500$.
- oneeyedpigeon 13y agoI'm curious: how much time would you say you worked on researching and identifying this bug? BTW, I don't begrudge you the payout one little bit, no matter how long you spent on it; such an amount is change down the back of the sofa for facebook, and the potential impact of the bug means they got a great deal!
- reginaldo 13y agoWell, I originally found the OpenID bug in 2012, but hadn't noticed Facebook was vulnerable until very recently. After I found their OpenID endpoint, the hardest part was getting them to make me a Yadis discover request. Then I had to squash a little bug in the exploit. Most of the time was spent re-reading the OpenID spec. I'd say total amount of work (including the time it took me to write the post) was about 2 days. As I said in the post, I already had a strong suspicion that, once I could read files, escalating to RCE would be easy. But I decided not to do it without permission and they fixed the bug very quickly. As much as I'd loved to actually see the output of an ls or something like that, I think I made the right call.
- danoc 13y agoHere's a permanent link: https://www.facebook.com/BugBounty/posts/778897822124446?stream_ref=10 https://www.facebook.com/BugBounty/posts/778897822124446?str...