The severity of security vulnerabilities should be judged on their context, not on their classification or category.
Think it was this one: http://exfiltrated.com/research-Instagram-RCE.php (actually it's even worse than I thought with Facebook threatening legal action against him)
If Facebook wanted to discourage pivoting access, they should have clearly stated so as Google and Microsoft have.
There's a whole thread on HN about this.
Here's Alex Stamos' writeup:
https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...
>In the case of Facebook, the rules can be seen at https://www.facebook.com/whitehat. There is no rule which states what to do when a vulnerability is discovered, but there are several which imply that my testing was valid. These include: Report a bug that could ... enable access to a system within our infrastructure Remote Code Execution Privilege Escalation Provisioning Errors
We both agree the initial RCE was in-scope. The researcher reported the RCE immediately, then reported the privilege escalation by weak user passwords, then reported the API key escalation.
Moreover, you're factually incorrect about the "fit of pique." The researcher stopped poking around immediately after receiving the email; he simply continued before Facebook contacted him. When Alex said,
Please be mindful that taking additional action after locating a bug violates our bounty policy.
There was no reference whatsoever to that policy in the official Bug Bounty guidelines. Alex fibbed. Indeed, how is a canonically "in-scope" privilege escalation supposed to work if researchers are to stop at the first bug?
Lastly, if Facebook's idea of defense-in-depth is a master API key to all Instagram S3 buckets, accessible from a simple diagnostic panel, any bug bounty program is merely window-dressing.
Remember, he didn't simply pivot. He back-pocketed credentials, didn't tell anyone he had them, and used them later to hit out-of-scope systems. Nobody is OK with that.
You've changed my view.
>He back-pocketed credentials, didn't tell anyone he had them
It should be assumed that any data on the pwned server is now accessible to attacker, just like in any real world scenario.
It's pentesting not penthieving. That's like saying military training is useless because they don't actually kill people.
He didn't say that at all. Your thesis here is that preventative discovery has no utility if it does not perfectly simulate real world conditions. That's a pretty extreme position; I don't think you'll sell many people on it.
> It should be assumed that any data on the pwned server is now accessible to attacker, just like in any real world scenario.
I think you'll have a hard time finding companies who are okay with security professionals taking sensitive data for themselves just because they're reporting a vulnerability.
Regardless, I feel like he deserves at least $15,000 for this, since it is full RCE.
"09.08.2018 20:10 CEST : a 5000$ bounty is awarded – the server was in a separate VLAN with no users’ specific data."
Please don't insinuate that someone hasn't read an article.