TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Facebook Bug Bounties – Unofficial Treasure Map

65 pointsby phwdalmost 9 years ago

4 comments

downandoutalmost 9 years ago
He forgot to mention m.facebook.com . There have been many issues over the years with the mobile site that didn&#x27;t exist on the main site. Examples:<p>1) You could invite <i>anyone</i> to a Facebook event via their Facebook ID by simply doing an HTTP post of Facebook ID&#x27;s to the event invitation script on this domain, but not on the main site. For some reason, on the mobile site they didn&#x27;t implement the check to see if you were actually friends with the invitee. Since FB sends an email to each invitee, this was an enormous spamming loophole for quite a while.<p>2) For a long time, there was no frame-breaking script on m.facebook.com. You could clickjack essentially anything on Facebook this way. Years ago I did a proof-of-concept on this where I clickjacked a platform app authorization, which let me receive the name, email, and other profile info of any user that did nothing more than click the X button on an annoying overlay I put on the screen.
评论 #11881677 未加载
评论 #11881569 未加载
tetrepalmost 9 years ago
Nice. Although I&#x27;m still on the fence about bug bounties at their current price, as I can&#x27;t help but see this as potentially manipulative, like hackathons where a company owns what you make, this guided hacking seems to be taking advantage of people&#x27;s passions in order to underpay them for work.<p>But, I can&#x27;t really say it&#x27;s underpaid, as I have no idea what the black market for exploits is like, so maybe they are fairly paid.
评论 #11881069 未加载
评论 #11880992 未加载
Lukas1994almost 9 years ago
&quot;Facebook’s internal network where employees turn those gears so you can scroll past that “10 Things You Love About Potatoes” BuzzFeed article one more time.&quot;
spejsonalmost 9 years ago
So I assume they won&#x27;t give a bounty, if somebody finds a bug like the possibility of calling their testing tool trough a chat message?
评论 #11880996 未加载