Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
franjkovic
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
Getting any Facebook user's friend list and partial payment card details
(josipfranjkovic.com)
416 points
by
franjkovic
9y ago
|
91 comments
2.
▲
Taking over Facebook accounts using Free Basics partner portal
(josipfranjkovic.com)
1 points
by
franjkovic
9y ago
|
0 comments
3.
▲
Hacking Facebook accounts using CSRF in Oculus-Facebook integration
(josipfranjkovic.com)
5 points
by
franjkovic
9y ago
|
0 comments
4.
▲
by
franjkovic
10y ago
Every Twitter's bounty amount is divisible by 140.
5.
▲
by
franjkovic
10y ago
I wanted to move from Blogspot to a personal domain, but kept delaying it for a long time.
6.
▲
by
franjkovic
10y ago
>how many hours did you spend researching this? Two to three hours discovering and writing the initial report, couple more hours (unsuccessfully) trying to escalate it using pre-approved apps. >I think $5,000 is a joke This is still $
7.
▲
by
franjkovic
10y ago
The bug was reported on December 8th, 2015 and fixed on February 18th, 2016 which is an unusually long time for Facebook. The bounty reached my account during the middle of March, but Facebook has recently changed their bounty payment proce
8.
▲
Stealing Facebook access_tokens using CSRF in device login flow
(josipfranjkovic.com)
127 points
by
franjkovic
10y ago
|
82 comments
9.
▲
by
franjkovic
10y ago
The post is interesting, but I do not know why people assume they would get a bounty for a security report if the company does not have responsible disclosure / bounty program.
10.
▲
by
franjkovic
11y ago
I'd say it does. Not interact with other accounts without the consent of their owners. Edit: whoops I mis-read this a bit, but the point still stands - he escalated using AWS keypair that did not belong to him, and he had no consent
11.
▲
The easiest bug bounties I have won
(josipfranjkovic.blogspot.com)
145 points
by
franjkovic
11y ago
|
27 comments
12.
▲
by
franjkovic
11y ago
I think they did not reward me because you cannot really hurt anyone by having multiple usernames.
13.
▲
by
franjkovic
11y ago
Thanks! I reported the bug to security@ email, and one of your team's members replied on the same day (January 6th). Either way, good job on fixing this really fast. I wish more teams are as responsive as yours.
14.
▲
by
franjkovic
11y ago
Facebook puts out stats from their bug bounty program once a year. Most of bugs are invalid reports - in 2013 they had 14,763 reports, with 687 being valid. ( https://www.fb.com/818902394790655 ) They probably got a couple pe
15.
▲
by
franjkovic
11y ago
The bounty actually surprised me, too. I expected between $1000-$2000. That is one of reasons I like reporting bugs to Facebook - they pay really good, critical bugs are fixed really fast (<1 day). One time they paid me $5000 for a bug I
16.
▲
Race conditions on Facebook, DigitalOcean and others (fixed)
(josipfranjkovic.blogspot.com)
294 points
by
franjkovic
11y ago
|
88 comments
17.
▲
by
franjkovic
12y ago
I agree with this, too. Personally, I would probably do the same. A day of breaking small part of site vs killing local file read seems like a good trade.
18.
▲
by
franjkovic
12y ago
HN, I am wondering about your thoughts on the $5500 bounty. This is a bug that affected third party system on Facebook's servers, and the network was locked down. I could have gained access to resume analysis software and maybe resume
19.
▲
by
franjkovic
12y ago
Yeah. In the 1 day timeframe between temp and permanent fix you could not upload resume, which is a breaking change for end users. But, I think it was pushed because it was Sunday and Careers team was not on site to properly/permanentl
20.
▲
Reading local files from Facebook's server (fixed)
(josipfranjkovic.blogspot.com)
44 points
by
franjkovic
12y ago
|
19 comments
21.
▲
Step-by-step: exploiting SQL injection(s) in Oculus' website
(josipfranjkovic.blogspot.com)
1 points
by
franjkovic
12y ago
|
0 comments
22.
▲
by
franjkovic
12y ago
Great bug, congratz! I saw that request when going through iphone.facebook.com, but never tried anything there... I assume it worked on all x/mobile/m/touch/iphone.facebook.com?
23.
▲
by
franjkovic
13y ago
Just added timeline for the report on blog.
24.
▲
by
franjkovic
13y ago
I agree with this - yet BB programs are still very successful. Why? Because not everyone who knows about websec has a job in the field. The second thing is, $500 as a minimum reward may seem small in 1st world countries, but in the rest it
25.
▲
Facebook bug bounty: secondary damage bugs and fairness
(josipfranjkovic.blogspot.com)
60 points
by
franjkovic
13y ago
|
10 comments
26.
▲
by
franjkovic
13y ago
Redirect URL when you give access to Facebook is different for other email providers. Hotmail (that is, Outlook) is the only one that worked as far as I know - I have tested Gmail and yahoo, but neither of them were exploitable (there is al
27.
▲
by
franjkovic
13y ago
You can read about all kinds of bugs and "bugs" I found in bounty programs on my old blog, too http://josipfranjkovic.blogspot.com/
28.
▲
by
franjkovic
13y ago
I spend 4-5 hours a week hunting for bugs. The "session" I found this bug in was around 2 hours long.
29.
▲
by
franjkovic
13y ago
Actually I waited until we pushed Pyxio website on-line. Since I am not native English speaker, what would be best replacement for current title?
30.
▲
by
franjkovic
13y ago
12,500$. (More than)Good enough for me, takes a year of work on average salary to get this much money in my country.
More ›