Skip to main content

Bug bounty hunter scores on Facebook and turns in another hacker

dell secureworks prices hacker keyboard 2 970x0
Facebook bug hunter finds another hacker's trail Image used with permission by copyright holder
While earning a $10,000 bounty, a penetration tester called Orange Tsai discovered another hacker’s backdoor already in place on a Facebook server, as reported by The Register. Orange Tsai turned in the other hacker’s mischief along with O.T.’s own success at cracking the server. Just another day in the life of professional bounty hacker.

Facebook’s bug bounty program pays rewards to anyone who finds and documents problems with its websites or systems. The rules for the program are detailed along with a long list of eligible websites, apps, and services. Fair game Facebook assets include Facebook.com, Instagram.com, and Oculus.com. WhatsApp, LiveRail, and Atlas aren’t included, so if you’re hacking for a bounty, hack elsewhere.

Orange Tsai works for Taiwan-based Devcore and published the full details of the hunt on a company blog. O.T. hacked into a Facebook staff server. Once inside, O.T. found a backdoor left by another hacker, along with code that could exploit Facebook staff credentials.

Orange Tsai reported the other hacker’s access when turning in his own bug report. After researching the reports, Facebook security engineer Reginaldo Silva discovered they already knew of the other hacker. That person is also part of their bug hunt program.

“We determined that the activity Orange detected was in fact from another researcher who participates in our bounty program. Neither of them were (sic) able to compromise other parts of our infrastructure, so the way we see it, it’s a double win: two competent researchers assessed the system, one of them reported what he found to us and got a good bounty, none of them were able to escalate access,” said Silva.

So Orange Tsai was paid for breaking into the Facebook server and also recognized for finding bug hunter tracks. In addition the money, Facebook recognized Orange Tsai on its official bug hunt thank you list.

Editors' Recommendations

Bruce Brown
Digital Trends Contributing Editor Bruce Brown is a member of the Smart Homes and Commerce teams. Bruce uses smart devices…
Apple pays $75,000 to hacker for discovery of exploits to hijack iPhone camera
iPhone 11 Pro Max vs. iPhone XS Max

Apple awarded $75,000 to a hacker who discovered exploits that allowed him to hijack the cameras of iPhones and Macs.

Security researcher and former Amazon Web Services security engineer Ryan Pickren disclosed at least seven zero-day vulnerabilities in Safari to Apple, according to Forbes. Three of these vulnerabilities may be used to hijack the cameras of iOS and macOS devices.

Read more
Facebook bug caused valid coronavirus articles to be marked as spam
facebook, facebook local news

Facebook scrambled to deal with a News Feed bug on Tuesday that filtered out legitimate news articles, including some about the coronavirus, formally known as COVID-19.

The flaw incorrectly identified a number of valid articles as spam, blocking links to news sites and preventing people from sharing the articles with others.

Read more
Online platforms like Facebook are losing yet another ‘infodemic’ war
Man in Wuhan wearing a mask amid coronavirus outbreak

As the world grapples with the coronavirus outbreak, the overlords of the internet’s biggest communication channels have been busy waging a different war: One against misinformation. The COVID-19 epidemic, which has so far infected nearly 98,000 people in 86 countries, has rapidly sparked yet another "infodemic" for online platforms like Facebook and YouTube, inundating them with an around-the-clock avalanche of misleading ads, fake news, conspiracy theory posts, and a whole lot more.

(For the uninitiated, an infodemic is a large amount of information about a problem that is viewed as being a detriment to its solution.)

Read more