HNHacker News
TopNewBestAskShowJobs

franjkovic

1,114 karma · joined October 20, 2013

[ my public key: https://keybase.io/josipfranjkovic; my proof: https://keybase.io/josipfranjkovic/sigs/4EYnl7a6Vko4DGKQFypdzXwAxT-YnFN8DEc5X34RttQ ]

My security blog: https://www.josipfranjkovic.com

submissionscomments
franjkovic··on Twitter's Vine source code dump
Every Twitter's bounty amount is divisible by 140.
franjkovic··on Stealing Facebook access_tokens using CSRF in device login flow
I wanted to move from Blogspot to a personal domain, but kept delaying it for a long time.
franjkovic··on Stealing Facebook access_tokens using CSRF in device login flow
>how many hours did you spend researching this?

Two to three hours discovering and writing the initial report, couple more hours (unsuccessfully) trying to escalate it using pre-approved apps.

>I think $5,000 is a joke

This is still $5,000 more than I would get reporting a similar bug to 99.999% of companies, and I am OK with the bounty. Here is good comment on the topic of bug bounty rewards: https://news.ycombinator.com/item?id=11249173

franjkovic··on Stealing Facebook access_tokens using CSRF in device login flow
The bug was reported on December 8th, 2015 and fixed on February 18th, 2016 which is an unusually long time for Facebook. The bounty reached my account during the middle of March, but Facebook has recently changed their bounty payment processor to Bugcrowd, and now they have weekly payments.
franjkovic··on The Bank Job – breaking a mobile banking application
The post is interesting, but I do not know why people assume they would get a bounty for a security report if the company does not have responsible disclosure / bounty program.
franjkovic··on Bug Bounty Ethics
I'd say it does.

Not interact with other accounts without the consent of their owners.

Edit: whoops I mis-read this a bit, but the point still stands - he escalated using AWS keypair that did not belong to him, and he had no consent of the owner.

franjkovic··on Race conditions on Facebook, DigitalOcean and others (fixed)
I think they did not reward me because you cannot really hurt anyone by having multiple usernames.
franjkovic··on Race conditions on Facebook, DigitalOcean and others (fixed)
Thanks! I reported the bug to security@ email, and one of your team's members replied on the same day (January 6th). Either way, good job on fixing this really fast. I wish more teams are as responsive as yours.
franjkovic··on Race conditions on Facebook, DigitalOcean and others (fixed)
Facebook puts out stats from their bug bounty program once a year. Most of bugs are invalid reports - in 2013 they had 14,763 reports, with 687 being valid.

(https://www.fb.com/818902394790655)

They probably got a couple people working exclusively on bug bounty reports. I also have to say they did a great job changing communication channels from emails to tickets which show in /support/, it is way easier now. The downside is that you must have a Facebook account, not sure if it was needed before the change.

franjkovic··on Race conditions on Facebook, DigitalOcean and others (fixed)
The bounty actually surprised me, too. I expected between $1000-$2000. That is one of reasons I like reporting bugs to Facebook - they pay really good, critical bugs are fixed really fast (<1 day).

One time they paid me $5000 for a bug I never could have found, but they did internally based on my low severity report. (http://josipfranjkovic.blogspot.com/2013/11/facebook-bug-bou...)

franjkovic··on Reading local files from Facebook's server (fixed)
I agree with this, too. Personally, I would probably do the same. A day of breaking small part of site vs killing local file read seems like a good trade.
franjkovic··on Reading local files from Facebook's server (fixed)
HN, I am wondering about your thoughts on the $5500 bounty. This is a bug that affected third party system on Facebook's servers, and the network was locked down. I could have gained access to resume analysis software and maybe resume uploads themselves. There was a small to none chance I could get Facebook internal code or binaries. So, was the bounty enough?
franjkovic··on Reading local files from Facebook's server (fixed)
Yeah. In the 1 day timeframe between temp and permanent fix you could not upload resume, which is a breaking change for end users.

But, I think it was pushed because it was Sunday and Careers team was not on site to properly/permanently fix the bug.

franjkovic··on Hacking Facebook’s Legacy API, Part 1: Making Calls on Behalf of Any User
Great bug, congratz!

I saw that request when going through iphone.facebook.com, but never tried anything there... I assume it worked on all x/mobile/m/touch/iphone.facebook.com?

franjkovic··on Facebook bug bounty: secondary damage bugs and fairness
Just added timeline for the report on blog.
franjkovic··on Facebook bug bounty: secondary damage bugs and fairness
I agree with this - yet BB programs are still very successful. Why? Because not everyone who knows about websec has a job in the field. The second thing is, $500 as a minimum reward may seem small in 1st world countries, but in the rest it is close to the average monthly pay.
franjkovic··on Facebook CSRF leading to full account takeover (fixed)
Redirect URL when you give access to Facebook is different for other email providers. Hotmail (that is, Outlook) is the only one that worked as far as I know - I have tested Gmail and yahoo, but neither of them were exploitable (there is also chance I missed something, so it is worth checking again).
franjkovic··on Facebook CSRF leading to full account takeover (fixed)
You can read about all kinds of bugs and "bugs" I found in bounty programs on my old blog, too http://josipfranjkovic.blogspot.com/
franjkovic··on Facebook CSRF leading to full account takeover (fixed)
I spend 4-5 hours a week hunting for bugs.

The "session" I found this bug in was around 2 hours long.

franjkovic··on Facebook CSRF leading to full account takeover (fixed)
Actually I waited until we pushed Pyxio website on-line. Since I am not native English speaker, what would be best replacement for current title?
franjkovic··on Facebook CSRF leading to full account takeover (fixed)
12,500$. (More than)Good enough for me, takes a year of work on average salary to get this much money in my country.