Silkroad Online Forums

A community forum for the free online game Silkroad Online. Discuss Silkroad Online, read up on guides, and build your character and skills.

Faq Search Members Chat  Register Profile Login

All times are UTC




Post new topic Reply to topic  [ 14 posts ] 
Author Message
 Post subject: Facebook Bug Bounty
PostPosted: Fri Sep 02, 2011 10:13 am 
Loyal Member
User avatar
Offline

Joined: May 2009
Posts: 1848
Location:
Leagueoflegends
http://www.facebook.com/whitehat/bounty/

Quote:
To show our appreciation for our security researchers, we offer a monetary bounty for certain qualifying security bugs. Here's how it works:

Eligibility
To qualify for a bounty, you must:
Adhere to our Responsible Disclosure Policy:
... give us a reasonable time to respond to your report before making any information public and make a good faith effort to avoid privacy violations, destruction of data and interruption or degradation of our service during your research ...
Be the first person to responsibly disclose the bug
Report a bug that could compromise the integrity or privacy of Facebook user data, such as:
Cross-Site Scripting (XSS)
Cross-Site Request Forgery (CSRF/XSRF)
Remote Code Injection
Reside in a country not under any current U.S. Sanctions (e.g., North Korea, Libya, Cuba, etc.)
Our security team will assess each bug to determine if qualifies.

Rewards
A typical bounty is $500 USD
We may increase the reward for specific bugs
Only 1 bounty per security bug will be awarded

Exclusions
The following bugs aren't eligible for a bounty (and we don't recommend testing for these):
Security bugs in third-party applications (e.g., http://apps.facebook.com/[app_name])
Security bugs in third-party websites that integrate with Facebook
Security bugs in Facebook's corporate infrastructure
Denial of Service Vulnerabilities
Spam or Social Engineering techniques


Sounds interesting.

_________________
Hi


Top
 Profile  
 
 Post subject: Re: Facebook Bug Bounty
PostPosted: Fri Sep 02, 2011 10:38 am 
Site Contributor
User avatar
Offline

Joined: Jan 2006
Posts: 3606
Location:
Guildwars2
Looks like they are preparing for Anon.


Top
 Profile  
 
 Post subject: Re: Facebook Bug Bounty
PostPosted: Fri Sep 02, 2011 3:29 pm 
Veteran Member
User avatar
Offline

Joined: Apr 2008
Posts: 3452
Location:
Alps
$500 is moot. Seems more of a publicity stunt. If they really wanted someone to hack them they would offer closer to $5000. I doubt a major hacker would waste his time on that.

_________________
.curve wrote:
Unless Silkroad has a hole I can stick it in, I prefer spending money on the girlfriend.

Image
Image
Spoiler!


Top
 Profile  
 
 Post subject: Re: Facebook Bug Bounty
PostPosted: Fri Sep 02, 2011 5:10 pm 
Dom's Slut
User avatar
Offline

Joined: Aug 2006
Posts: 13791
Location:
Guildwars2
Wait, you have to be from North Korea?

_________________
ImageImageImage


Top
 Profile  
 
 Post subject: Re: Facebook Bug Bounty
PostPosted: Fri Sep 02, 2011 5:39 pm 
Forum Legend
User avatar
Offline

Joined: Sep 2008
Posts: 7923
Location:
Off Topic
Pretty cool idea... But "$500" seems pretty low for such a large site. Don't ya think?

_________________
Image


Top
 Profile  
 
 Post subject: Re: Facebook Bug Bounty
PostPosted: Fri Sep 02, 2011 6:48 pm 
Site Contributor
User avatar
Offline

Joined: Apr 2007
Posts: 2079
Location: Looking for my signature....
Am I naive or are they too lazy to look for their own bugs so instead of paying a guy 50$ an hour to look for specific bugs, hey tell 100,000,000 people to look for bugs so that a person getting payed 10$ an hour can filter hundres of thousands of emails that people will write a bunch of stupid useless bullshit to try to get $500? *sigh* what a lazy community we live in...

_________________
Image


Top
 Profile  
 
 Post subject: Re: Facebook Bug Bounty
PostPosted: Fri Sep 02, 2011 7:32 pm 
Loyal Member
User avatar
Offline

Joined: May 2009
Posts: 1848
Location:
Leagueoflegends
500$ is the minimum..

_________________
Hi


Top
 Profile  
 
 Post subject: Re: Facebook Bug Bounty
PostPosted: Fri Sep 02, 2011 8:46 pm 
Elite Member
User avatar
Offline

Joined: Aug 2006
Posts: 5985
Location: ...
CrimsonNuker wrote:
Wait, you have to be from North Korea?

Do they even have Internet there?

_________________
Image Image Image


Top
 Profile  
 
 Post subject: Re: Facebook Bug Bounty
PostPosted: Fri Sep 02, 2011 8:58 pm 
Senior Member
User avatar
Offline

Joined: Feb 2008
Posts: 4222
Location: Nowhere
K.K wrote:
500$ is the minimum..


It says a -typical- bounty is $500. Reward is pathetic even if that number changed to x4 more.

_________________
Image
Image
If being a loser means not playing Silkroad all day.. lulwut?


Top
 Profile  
 
 Post subject: Re: Facebook Bug Bounty
PostPosted: Fri Sep 02, 2011 10:31 pm 
Frequent Member
User avatar
Offline

Joined: May 2008
Posts: 1374
Location: Hiding
I think the concept is that instead of having the "hacker communities" identify flaws and them simply do nothing productive to help facebook, it offers them a form of incentive to use their skills for a purpose. If I was a hacker, or whatever, and I spent my free time trolling around websites looking for flaws I would be thrilled to know that I could get $500 for doing what I normally do anyway. $500 is a lot more money than you think, imagine all the gummy bears you could buy with that! :D


Top
 Profile  
 
 Post subject: Re: Facebook Bug Bounty
PostPosted: Fri Sep 02, 2011 10:31 pm 
Frequent Member
User avatar
Offline

Joined: May 2008
Posts: 1374
Location: Hiding
I think the concept is that instead of having the "hacker communities" identify flaws and them simply do nothing productive to help facebook, it offers them a form of incentive to use their skills for a purpose. If I was a hacker, or whatever, and I spent my free time trolling around websites looking for flaws I would be thrilled to know that I could get $500 for doing what I normally do anyway. $500 is a lot more money than you think, imagine all the gummy bears you could buy with that! :D


Top
 Profile  
 
 Post subject: Re: Facebook Bug Bounty
PostPosted: Fri Sep 02, 2011 10:46 pm 
Elite Member
User avatar
Offline

Joined: Aug 2006
Posts: 5985
Location: ...
MrTwilliger wrote:
I think the concept is that instead of having the "hacker communities" identify flaws and them simply do nothing productive to help facebook, it offers them a form of incentive to use their skills for a purpose. If I was a hacker, or whatever, and I spent my free time trolling around websites looking for flaws I would be thrilled to know that I could get $500 for doing what I normally do anyway. $500 is a lot more money than you think, imagine all the gummy bears you could buy with that! :D


U could even buy loads of these:
.

_________________
Image Image Image


Top
 Profile  
 
 Post subject: Re: Facebook Bug Bounty
PostPosted: Sat Sep 03, 2011 12:14 am 
Senior Member
User avatar
Offline

Joined: Feb 2008
Posts: 4222
Location: Nowhere
MrTwilliger wrote:
$500 is a lot more money than you think, imagine all the gummy bears you could buy with that! :D


Not when you can find a potential bug that could ruin facebook for day(s) and get paid $500 for it, leak information, etc etc. There's a reason why they hire people to try and hack their system. There's a reason why they hire people that hacked their system.

This is just a way to fix dangerous bugs against facebook while paying little to nothing.

_________________
Image
Image
If being a loser means not playing Silkroad all day.. lulwut?


Top
 Profile  
 
 Post subject: Re: Facebook Bug Bounty
PostPosted: Sat Sep 03, 2011 12:41 am 
Addicted Member
User avatar
Offline

Joined: Jan 2011
Posts: 2626
Location: Home ._.
Toshiharu wrote:
MrTwilliger wrote:
$500 is a lot more money than you think, imagine all the gummy bears you could buy with that! :D


Not when you can find a potential bug that could ruin facebook for day(s) and get paid $500 for it, leak information, etc etc. There's a reason why they hire people to try and hack their system. There's a reason why they hire people that hacked their system.

This is just a way to fix dangerous bugs against facebook while paying little to nothing.

I guess they would pay thousands for such a bug depending on what ruin means.

_________________
So in the first week in college i went with jeans and the pajama's shirt. Didn't notice what i was wearing till after i returned home.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 14 posts ] 

All times are UTC


Who is online

Users browsing this forum: No registered users and 47 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group