Bug hunter exposes security hole, Facebook cries foul

Image
IANS New York
Last Updated : Dec 21 2015 | 2:28 PM IST

A security researcher who unearthed a major Instagram hole has got into trouble with Facebook that accused him of unethical behaviour.

Wesley Wineberg, a well-known bug hunter, was checking the vulnerability of an exposed Amazon server when he found a hole that could allow hackers to run code remotely, and submitted a ticket to the bug bounty team, Engadget.com reported.

After confirming the bug, he decided to dig a bit deeper, and then things took an ugly turn. He managed to crack some weak employee passwords, and submitted another report. Using that info, he obtained a key that allowed him to access server files.

To demonstrate the extent of the vulnerability, he downloaded several "buckets" of non-user data from Instagram's Amazon servers.

The data, he discovered, gave him access to source code and secret authentication codes.

"To say that I had gained access to basically all of Instagram's secret key material would probably be a fair statement," he wrote in a blog post.

Having paid Wineberg $2,500 for discovering the earlier bug, Facebook was, this time around, far from grateful.

It declined to pay him for the later bug submissions, saying he had violated the terms of its bug bounty programme.

In a Facebook post, CSO Alex Stamos wrote: "Intentional exfiltration of data is not authorized by our bug bounty programme, is not useful in understanding and addressing the core issue, and was not ethical behaviour by Wes."

Stamos was also reported as telling Synack's CEO -- Wineberg's employer -- that "we could not allow Wes to set a precedent that anybody can exfiltrate unnecessary amounts of data and call it a part of legitimate bug research".

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Dec 21 2015 | 2:14 PM IST

Next Story