TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

How I got a $3,500 USD Facebook Bug Bounty

145 点作者 fransr超过 12 年前

9 条评论

shimon_e超过 12 年前
I submitted a report to facebook about privacy setting circumvention. Didn't receive a response. Didn't receive a bounty. Facebook DID fix the bug after some months.<p>Feel a bit cheated that a billion dollar company couldn't take the time to respond... if I had the time I'd follow up with them.
评论 #4986959 未加载
评论 #4986391 未加载
评论 #4985949 未加载
评论 #4989776 未加载
评论 #4985755 未加载
评论 #4985831 未加载
killahpriest超过 12 年前
Whenever people teaching others about security mention XSS, I've always wondered does it really even happen in the real world? I'm sure everybody escapes their input.<p>Turns out there's a reason XSS is so often mentioned. Even Dropbox and Facebook fell prey to it (although in this case the input wasn't from the web, but rather from their desktop application/service partner).
评论 #4987843 未加载
评论 #4985775 未加载
评论 #4986153 未加载
评论 #4985718 未加载
评论 #4988440 未加载
评论 #4986075 未加载
gklitt超过 12 年前
Props to Facebook for being so responsible about fixing this bug. After seeing so many blog posts about companies not responding to emails from whitehats finding XSS vulnerabilities (<a href="http://www.troyhunt.com/2012/08/why-xss-is-serious-business-and-why.html" rel="nofollow">http://www.troyhunt.com/2012/08/why-xss-is-serious-business-...</a>), it's comforting to see someone take such reports seriously.
评论 #4989944 未加载
tommi超过 12 年前
I bet Blackhat Vulnerability Program would've payed lot more.
评论 #4986081 未加载
评论 #4985636 未加载
评论 #4989791 未加载
评论 #4986087 未加载
评论 #4986060 未加载
jbverschoor超过 12 年前
lol.. I found a bug in paypal which allowed me to transfer funds from one account to another, even though this was prohibited.<p>I got nothing. Maybe next time I'll just post this stuff for random people on twitter to find
评论 #4988215 未加载
tomjen3超过 12 年前
Wauw, so all that happens if you save dropboxs ass is that you get a special mention on their special page that very few people know about?<p>Why even bother to tell them then?
评论 #4987754 未加载
评论 #4987844 未加载
评论 #4988935 未加载
评论 #4988476 未加载
评论 #4986802 未加载
评论 #4988936 未加载
tokipin超过 12 年前
wait facebook has like millions of bugs -.- though maybe UI glitches aren't considered bugs
wilfra超过 12 年前
I submitted an error (and a solution) in their open graph docs that caused a bug if anybody copy/pasted the code from their site. The error was fixed within hours, however I never got any money or even an email :(
评论 #4986113 未加载
评论 #4985829 未加载
robmcvey超过 12 年前
BAM!