Facebook Bug Bounty

Anything else. Post a funny site or tell us about yourself. Discuss current events or whatever else you want. Post off topic threads here.
Post Reply
User avatar
Vaya
Loyal Member
Posts: 1844
Joined: Thu May 21, 2009 10:24 am
Quick Reply: Yes
Location: leagueoflegends

Facebook Bug Bounty

Post by Vaya »

http://www.facebook.com/whitehat/bounty/

To show our appreciation for our security researchers, we offer a monetary bounty for certain qualifying security bugs. Here's how it works:

Eligibility
To qualify for a bounty, you must:
Adhere to our Responsible Disclosure Policy:
... give us a reasonable time to respond to your report before making any information public and make a good faith effort to avoid privacy violations, destruction of data and interruption or degradation of our service during your research ...
Be the first person to responsibly disclose the bug
Report a bug that could compromise the integrity or privacy of Facebook user data, such as:
Cross-Site Scripting (XSS)
Cross-Site Request Forgery (CSRF/XSRF)
Remote Code Injection
Reside in a country not under any current U.S. Sanctions (e.g., North Korea, Libya, Cuba, etc.)
Our security team will assess each bug to determine if qualifies.

Rewards
A typical bounty is $500 USD
We may increase the reward for specific bugs
Only 1 bounty per security bug will be awarded

Exclusions
The following bugs aren't eligible for a bounty (and we don't recommend testing for these):
Security bugs in third-party applications (e.g., http://apps.facebook.com/[app_name])
Security bugs in third-party websites that integrate with Facebook
Security bugs in Facebook's corporate infrastructure
Denial of Service Vulnerabilities
Spam or Social Engineering techniques


Sounds interesting.
Hi

User avatar
Avalanche
Site Contributor
Posts: 3606
Joined: Mon Jan 30, 2006 4:08 am
Quick Reply: Yes
Location: guildwars2

Re: Facebook Bug Bounty

Post by Avalanche »

Looks like they are preparing for Anon.

User avatar
Goseki
Veteran Member
Posts: 3452
Joined: Mon Apr 07, 2008 2:45 am
Quick Reply: Yes
Location: Alps

Re: Facebook Bug Bounty

Post by Goseki »

$500 is moot. Seems more of a publicity stunt. If they really wanted someone to hack them they would offer closer to $5000. I doubt a major hacker would waste his time on that.
.curve wrote:Unless Silkroad has a hole I can stick it in, I prefer spending money on the girlfriend.

Image
Image
Spoiler!

User avatar
CrimsonNuker
Dom's Slut
Posts: 13791
Joined: Sun Aug 06, 2006 3:31 am
Quick Reply: Yes
Location: guildwars2

Re: Facebook Bug Bounty

Post by CrimsonNuker »

Wait, you have to be from North Korea?
ImageImageImage

User avatar
*BlackFox
Forum Legend
Posts: 7921
Joined: Wed Sep 03, 2008 12:55 pm
Quick Reply: Yes
Location: Off Topic

Re: Facebook Bug Bounty

Post by *BlackFox »

Pretty cool idea... But "$500" seems pretty low for such a large site. Don't ya think?
Image

User avatar
Majorharper
Site Contributor
Posts: 2079
Joined: Sun Apr 22, 2007 8:19 am
Quick Reply: Yes
Location: Looking for my signature....

Re: Facebook Bug Bounty

Post by Majorharper »

Am I naive or are they too lazy to look for their own bugs so instead of paying a guy 50$ an hour to look for specific bugs, hey tell 100,000,000 people to look for bugs so that a person getting payed 10$ an hour can filter hundres of thousands of emails that people will write a bunch of stupid useless bullshit to try to get $500? *sigh* what a lazy community we live in...
Image

User avatar
Vaya
Loyal Member
Posts: 1844
Joined: Thu May 21, 2009 10:24 am
Quick Reply: Yes
Location: leagueoflegends

Re: Facebook Bug Bounty

Post by Vaya »

500$ is the minimum..
Hi

User avatar
omier
Elite Member
Posts: 5985
Joined: Thu Aug 24, 2006 9:33 pm
Quick Reply: Yes
Location: ...

Re: Facebook Bug Bounty

Post by omier »

CrimsonNuker wrote:Wait, you have to be from North Korea?

Do they even have Internet there?
Image Image Image

User avatar
Toshiharu
Senior Member
Posts: 4222
Joined: Fri Feb 15, 2008 1:55 am
Quick Reply: Yes
Location: Nowhere

Re: Facebook Bug Bounty

Post by Toshiharu »

K.K wrote:500$ is the minimum..


It says a -typical- bounty is $500. Reward is pathetic even if that number changed to x4 more.
Image
Image
If being a loser means not playing Silkroad all day.. lulwut?

User avatar
MrTwilliger
Frequent Member
Posts: 1374
Joined: Fri May 16, 2008 8:27 am
Quick Reply: Yes
Location: Hiding

Re: Facebook Bug Bounty

Post by MrTwilliger »

I think the concept is that instead of having the "hacker communities" identify flaws and them simply do nothing productive to help facebook, it offers them a form of incentive to use their skills for a purpose. If I was a hacker, or whatever, and I spent my free time trolling around websites looking for flaws I would be thrilled to know that I could get $500 for doing what I normally do anyway. $500 is a lot more money than you think, imagine all the gummy bears you could buy with that! :D

User avatar
MrTwilliger
Frequent Member
Posts: 1374
Joined: Fri May 16, 2008 8:27 am
Quick Reply: Yes
Location: Hiding

Re: Facebook Bug Bounty

Post by MrTwilliger »

I think the concept is that instead of having the "hacker communities" identify flaws and them simply do nothing productive to help facebook, it offers them a form of incentive to use their skills for a purpose. If I was a hacker, or whatever, and I spent my free time trolling around websites looking for flaws I would be thrilled to know that I could get $500 for doing what I normally do anyway. $500 is a lot more money than you think, imagine all the gummy bears you could buy with that! :D

User avatar
omier
Elite Member
Posts: 5985
Joined: Thu Aug 24, 2006 9:33 pm
Quick Reply: Yes
Location: ...

Re: Facebook Bug Bounty

Post by omier »

MrTwilliger wrote:I think the concept is that instead of having the "hacker communities" identify flaws and them simply do nothing productive to help facebook, it offers them a form of incentive to use their skills for a purpose. If I was a hacker, or whatever, and I spent my free time trolling around websites looking for flaws I would be thrilled to know that I could get $500 for doing what I normally do anyway. $500 is a lot more money than you think, imagine all the gummy bears you could buy with that! :D


U could even buy loads of these:
.
Image Image Image

User avatar
Toshiharu
Senior Member
Posts: 4222
Joined: Fri Feb 15, 2008 1:55 am
Quick Reply: Yes
Location: Nowhere

Re: Facebook Bug Bounty

Post by Toshiharu »

MrTwilliger wrote:$500 is a lot more money than you think, imagine all the gummy bears you could buy with that! :D


Not when you can find a potential bug that could ruin facebook for day(s) and get paid $500 for it, leak information, etc etc. There's a reason why they hire people to try and hack their system. There's a reason why they hire people that hacked their system.

This is just a way to fix dangerous bugs against facebook while paying little to nothing.
Image
Image
If being a loser means not playing Silkroad all day.. lulwut?

User avatar
The Invisible
Addicted Member
Posts: 2626
Joined: Sun Jan 23, 2011 1:28 pm
Quick Reply: Yes
Location: Home ._.

Re: Facebook Bug Bounty

Post by The Invisible »

Toshiharu wrote:
MrTwilliger wrote:$500 is a lot more money than you think, imagine all the gummy bears you could buy with that! :D


Not when you can find a potential bug that could ruin facebook for day(s) and get paid $500 for it, leak information, etc etc. There's a reason why they hire people to try and hack their system. There's a reason why they hire people that hacked their system.

This is just a way to fix dangerous bugs against facebook while paying little to nothing.

I guess they would pay thousands for such a bug depending on what ruin means.
So in the first week in college i went with jeans and the pajama's shirt. Didn't notice what i was wearing till after i returned home.

Post Reply

Return to “Off Topic Lounge”