Deleting any Facebook album
7xter.com
7xter.com
If anyone wants to try and replicate this sort of thing, consider this: the mobile applications (touch.facebook.com, iOS/Android apps) that Facebook use very often take advantage of legacy api calls and code that the main web application has long since disposed of.
A well known researcher, Stephen Sclafani ('ssclafani) receiced a bounty of $25,000 for arbitrary account takeover using the legacy api.
Legacy code is generally the first place to look for vulnerabilities. Legacy apis which are still allowed to exist for backwards compatibility are prime areas to search for bug bounties.
Good luck.
A common example: any handoff between a marketing site (or email) and a SaaS app more complicated than "Clicking this unchanging link takes you to a login form" almost certainly involves two teams and was somebody's perceived least important thing to do that day.
Agreed. Touch/m.facebook.com have had major holes exist for long after they have been plugged on the main site. It was iframeable long after the main site wasn't (and thus subject to clickjacking). Also, for a long time you could invite anyone to events by Facebook ID by posting the correct calls to the mobile site, essentially without limit, even after the issue was fixed on the main site. Since custom messages could be embedded in the invitations, it was a spam free-for-all.
Paying out that sum of money to increase the number of people searching for security flaws is quite smart.
These sorts of things are publicly verifiable - Michal Zalewski has commented on it before as a member of the Google appsec team, and if you look on Twitter for writeups from the same folks you come to the same conclusion. I have in mind one particular friend who literally bankrupted a bug bounty in three hours.
Another security researcher by the name of Nicholas Gregoire earned $35,000 combined from Yahoo and Facebook for a single vulnerability in each company - both server-side request forgery. He found it in Yahoo's YQL console, then decided to look elsewhere for it in a very deterministic fashion, and came across it in Parse (Facebook). He found many more bugs in a period of a few months, but he explicitly didn't look as seriously as some people do, which entails actively tracking acquisitions by companies like Google and Facebook.
It can be something of a meat grinder, but finding bug bounties is extremely profitable work. Then of course, having this work on a rèsumè is an immediate step up for getting interviews.
"I made $10k just for a quick hack"[1] has enormous bragging value - it's both a large enough payout for that, and it can actually be used without going to jail. Much better than actually bringing Facebook down.
[1] It doesn't matter how much work went into finding the exploit, one can still brag about doing it left-handed in 5 minutes.
This isn't (generally) about the absolute dollar amount. It's a prestige thing, it's a pride thing, and it's an accomplishment thing. For the preponderance of people that participate in bug bounties, the money is probably very much secondary.
apps.facebook.com (Facebook Windows Store) is not in the scope of this bug bounty program though.
To be clear, the issue is: Windows users using the Windows search feature, or directly using the Windows Store, are presented with fake FB apps claiming to be official. Contacting MS support gets useless replies, as they are trying to pump their app counts. Meanwhile, normal users end up installing a potentially malicious app, claiming to be the official FB app. FB needs to send a takedown.
I say this since I went through this process myself about a year ago and the app I reported was taken down. full disclosure: I worked on the app store team, but didn't use any internal mechanism.
I've reported all sorts of things. In nearly every single case, they say they cannot do anything. Even when there's a fake DropBox app "by" "@Microsoft". In that case, the CSR told me to try re-installing the app, that it worked for him. Zero understanding of the issue.
I've found a fake Windows Update on the Store. Reporting it got a generic response, until I emailed the MS security folks. Then it was removed in a few minutes. Meanwhile, they suggest I "Leave a review" or email the developer. Idiotic.
Netflix went back and forth with MS at least 3 times. Amazon had issues as well. Other ISVs tell me they can simply not get MS to be responsive about things.
Disney was the funniest response. Despite being a major Store publisher, there's all sorts of fake Disney stuff online. When I spoke to the Disney Store about it, the final suggestion was "don't go on it [the Windows Store]". Neato.
It's obvious MS is just padding the app numbers and no review is actually happening. It's a shame, since it undermines all the work; the Windows Store is a joke even with casual users. (Like even meeting random people on a plane and asking.) I emailed Satya. I emailed the GM of the Store. I emailed the Dev evangelist pushing the "let's pay people in third world countries 4 months salary for publishing 20 shitty wrap-a-webpage apps" program. No replies.
Here's a gallery of some gems: http://imgur.com/a/xvqZg#0
But nothing beats this awesomeness: http://imgur.com/fLOWMI4
I really hope they enable an Android compat layer. Even if it's slow, A: tons of random utility apps will be available, B: MS can enforce some quality instead of quantity.
I find it hard to believe MS isn't aware of these issues, unless no one actually uses it (Win10 makes it more in-your-face, though). Someone must have a bonus that's tied to "published app count". Neither Apple nor Google have these issues. The Store is worse than the Android Marketplace was.
It would ultimately be the hapless users who suffer in some way.
However I'm not sure if the risk being caught is considered in this. If you can get let's say, X times more in the black market but also risk 10 or 20 or whatever years in jail as well, I'm not sure those 12.5k seem that bad.
Edit: Or maybe doing extortion on someone? but how much could you get by threatening to delete someone's photos? I'm guessing not much... no?
Any reference for this?
The half-life of this bug is ~0. As soon as Facebook becomes aware of it, it is nearly instantly fixed everywhere. This is very not the case if you get e.g. code execution on a version of Java which will take 50 months to completely disappear from the wild.
Plus they become good future recruiting targets.
Let's look through the challenges of selling a vulnerability that allows for arbitrary account takeover (much more serious than this):
0. Find the vulnerability. Assume that no one will find it by the time you find a third party buyer.
1. Look for a buyer. If you're not well-connected, you might stumble into an FBI honeypot (a sting operation) because you don't know what you're doing. But let's assume you know what you're doing and you find a buyer.
2. You negotiate a price. You don't receive much more than Facebook would pay you (if they even give you that much) for a few reasons:
a. The vulnerability can only be used on Facebook, so it's not vendor agnostic (compare Heartbleed, Shellshock);
b. The vulnerability has an extremely small window of capitalization - it will be discovered within a week of use, maybe less. The Facebook incident response team is spectacular.
c. You need to figure out a sufficient monetization strategy for distributing malware or spam using profiles that are taken over using this vulnerability. You have a week of use, much less if you try to take over accounts too aggressively. Now you're going up against all of Facebook's other protections - once you have the account, spreading malware will either be algorithmically discovered by Facebook or reported by other users.
With an organized crime unit composed of professional hackers, this might pay off. Maybe. And that is for one of the most serious bugs you can find. You're better off just taking what Facebook (generously) gives you.
The classical fallacy people fall into is believing that a web application vulnerability is worth much, especially the variety most tech companies have to offer. It's certainly serious, yes, but it's only worth what a market will pay for it. It's worth a lot to Facebook for brand integrity. It's not worth a lot to hackers looking to make money.
The only web applications that might be worth real money would be banks or government institutions (or similar platforms). Real money is found in vulnerabilities on desktop clients, especially memory corruption vulnerabilities, or in ubiquitous software that affects servers. You want to be able to compromise a user for use in a botnet or distribute malware to steal their money or personal information. Alternatively, you want to be able to attack, say, 30% of the websites on the internet with a wide variety of options after you get in.
Examples include:
• Vulnerabilities in Flash.
• Vulnerabilities in Python, Ruby or corresponding web frameworks.
• Code execution in iOS that allows a jailbreak (most sources indicate the going price for this is $500,000). Other vulnerabilities as well, such as compromising app store receipts or in-app purchase checks.
• Vulnerabilities in Android, up to and including code execution.
• A game over flaw in any number of ubiquitous software packages used on Linux servers with root access.
• A sandbox escape in OS X or Windows (you'll be paid more for Windows but both are lucrative).
I'm not asking if you can hypothesize such a market. I'm asking if you know about one actually existing.
It's been suggested to me that there is in fact at least one set of buyers for account takeover bugs. But they aren't monetizing those accounts.
I browsed through the site thinking there were some other interesting security posts.
Turns out this is the only post on the site. Then I did a Whois and this site was created 2 days ago. It's registered to laksshmanan51@gmail.com which is apparently the same guy on the post. Then I did a search on Google for laksshmanan51@gmail.com and there are search results with "You can earn huge using your Facebook page. Please let me know if you are interested. Shoot me a mail laksshmanan51@gmail.com"
This just doesn't pass the smell test with me, seems to me this guy just pwned a lot of people to get ad clicks or something else.
What do you do when you think a company would just fix the bug based on your report and not pay out anything? I have seen so many bugs in the wild like this. For example a site in the uk where I can get access to any account I wish.
Are there any data protection laws that would provide leverage? How would you make first contact with a company that doesn't advertise a bug bounty program?
Does this kind of email seem ok?
"Hi, I have seen a security vulnerability on your site. How do I report it? What do you pay?…
May you respond in the next 7 days or I will be forced to take this to xxx.org for the protection of your users"The most serious vulnerabilities I ever found (read: the greatest potential for exploitation) came from reports to companies without bug bounties, so I know the position you're in. But looking for payment in return for vulnerabilities outside of the context of a bug bounty sets a precedent for the wrong motivation and is inherently adversarial to the company. Do not fish for vulnerabilities, then try to hold out your report for payment. Whether or not you believe it is unethical is a matter of personal opinion I suppose (I believe it's unethical), but it is at least illegal.
Now, let me clarify: there is nothing wrong with giving a company a deadline before you go public. But 7 days is far too small of a deadline. 90 days is better. And if you do this, you don't seek payment, you do it because you're a professional security researcher who cares about their security, not because you're trying to make a quick buck.
When you find a vulnerability like this, you proceed carefully. Contact a software developer, or better yet, a security team member (if they have one) who is technically savvy enough to understand your report. It would be best to do this anonymously. Email is strongly preferable, but you can escalate to Twitter if it means being put in contact with the right person. Obviously this means asking for help with security on Twitter, not disclosing the vulnerability publicly.
What if you aren't a professional security researcher, though? I'm sure there are plenty of underpaid people out there who stumble onto bugs like this every so often. Yes, asking the company to give you money on threat of revealing the bug is definitely extortion, but you are assuming a little too much in this case I believe. Some people may truly need the money.
Again, thanks for the advice.
Wouldn't that strongly depend on how you found it? E.g if a friend sends you an invite to share files on dropboks.com (hypotetical dropbox like service) and you copy and paste only part of the link, you now have access to his files (think /mergers/dove-soap but you insert /mergers/ and get to see all his mergers). In this case you stumbled on a huge security issue but how did you do anything illegal?
Edit: I should probably expand on that. Telling a company that you know about a bug but won't tell them about it if they don't pay you and instead threaten to turn it over to other parties who may have more nefarious intentions is pretty much extortion and is likely illegal.
I understand that you'd want to make money out of it, but if the company offers no bug bounty, it's no good threatening them. If you do so, it'll likely trigger a hostile response.
Thanks.
Maybe the xxx.org came across wrong. My intention was a government organisation, nothing nefarious.
But is it my responsibility to spend time reporting this to them? Should I leave the vulnerability for others to take advantage of, if they come across it? How do I know that others aren't already doing so?
With this specific vulnerability it could be used it to build an address book of emails, {home,work}addresses, telephone numbers etc; given the nature of the app.
edit: And you're probably not going to get anything for what you found, but you'll get a thanks if you go around it right, and you'll get arrested or ignored if you don't. You might get some recognition too, and that's worth a lot when you are young.
Wonder if it's intentional, i.e.: If you are truly L337 then you'd work it out eventually, or it's some sort of HSTS type-thing.
https://www.facebook.com/whitehat/thanks
About 725 independent researchers contributed.
> Not reside in a country under any current U.S. Sanctions (e.g., North Korea, Libya, Cuba, etc.)
Keyword there is any. Some Russian officials are under U.S. sanctions, does that mean Russian citizens are not eligible for the bounty?
I ask cause according to Wikipedia[0], I reside in a country under U.S. sanctions but the sanctions apply to certain people instead of the entire country.
This isn't one of those vulnerabilities that relies on numerous seemingly unrelated steps and makes you wonder how the person ever thought it up.
Instead, this is security 101 stuff. Facebook simply wasn't making sure userFor(appKey) == owner(albumId). I would've assumed obvious holes like this don't even exist in the API. So, props to the author trying it out. Wish I had.
I'm not surprised the delete worked...
I really need to bring my curious nature back into the forefront.
I thought there would be more interesting security posts and this is the only post on the entire site.
The site was registered just 2 days ago, see http://www.whois.com/whois/7xter.com . Then if you search on Google for the email that registered the site (laksshmanan51@gmail.com) you get this http://apnahindisms.blogspot.mx/2014/09/bewafa-shayari-in-hi... that has "You can earn huge using your Facebook page. Please let me know if you are interested. Shoot me a mail laksshmanan51@gmail.com"
Find line of code containing bug and:
git blame -L2469,2469 -- app/core/shitty_auth.php | \
egrep -oh '[A-Z][a-z]+ [A-Z][a-z]+' | \
xargs -I {} python dock_monthly_pay.py \
--employee-name="{}" --amount=1041.67