franjkovic | 9 years ago | on: Twitter's Vine source code dump
franjkovic's comments
franjkovic | 9 years ago | on: Stealing Facebook access_tokens using CSRF in device login flow
franjkovic | 9 years ago | on: Stealing Facebook access_tokens using CSRF in device login flow
Two to three hours discovering and writing the initial report, couple more hours (unsuccessfully) trying to escalate it using pre-approved apps.
>I think $5,000 is a joke
This is still $5,000 more than I would get reporting a similar bug to 99.999% of companies, and I am OK with the bounty. Here is good comment on the topic of bug bounty rewards: https://news.ycombinator.com/item?id=11249173
franjkovic | 9 years ago | on: Stealing Facebook access_tokens using CSRF in device login flow
franjkovic | 9 years ago | on: The Bank Job – breaking a mobile banking application
franjkovic | 10 years ago | on: Bug Bounty Ethics
Not interact with other accounts without the consent of their owners.
Edit: whoops I mis-read this a bit, but the point still stands - he escalated using AWS keypair that did not belong to him, and he had no consent of the owner.
franjkovic | 11 years ago | on: Race conditions on Facebook, DigitalOcean and others (fixed)
franjkovic | 11 years ago | on: Race conditions on Facebook, DigitalOcean and others (fixed)
franjkovic | 11 years ago | on: Race conditions on Facebook, DigitalOcean and others (fixed)
(https://www.fb.com/818902394790655)
They probably got a couple people working exclusively on bug bounty reports. I also have to say they did a great job changing communication channels from emails to tickets which show in /support/, it is way easier now. The downside is that you must have a Facebook account, not sure if it was needed before the change.
franjkovic | 11 years ago | on: Race conditions on Facebook, DigitalOcean and others (fixed)
One time they paid me $5000 for a bug I never could have found, but they did internally based on my low severity report. (http://josipfranjkovic.blogspot.com/2013/11/facebook-bug-bou...)
franjkovic | 11 years ago | on: Reading local files from Facebook's server (fixed)
franjkovic | 11 years ago | on: Reading local files from Facebook's server (fixed)
franjkovic | 11 years ago | on: Reading local files from Facebook's server (fixed)
But, I think it was pushed because it was Sunday and Careers team was not on site to properly/permanently fix the bug.
franjkovic | 11 years ago | on: Hacking Facebook’s Legacy API, Part 1: Making Calls on Behalf of Any User
I saw that request when going through iphone.facebook.com, but never tried anything there... I assume it worked on all x/mobile/m/touch/iphone.facebook.com?
franjkovic | 12 years ago | on: Facebook bug bounty: secondary damage bugs and fairness
franjkovic | 12 years ago | on: Facebook bug bounty: secondary damage bugs and fairness
franjkovic | 12 years ago | on: Facebook CSRF leading to full account takeover (fixed)
franjkovic | 12 years ago | on: Facebook CSRF leading to full account takeover (fixed)
franjkovic | 12 years ago | on: Facebook CSRF leading to full account takeover (fixed)
The "session" I found this bug in was around 2 hours long.
franjkovic | 12 years ago | on: Facebook CSRF leading to full account takeover (fixed)