Mine bitcoin on their server just out of spite.
There were also SSH key files.
I’m not publishing the archive, keys, or session logs.
I submitted the report and findings using Meta’s bug bounty program. Meta marked the report “Not Applicable.”
Guess they don’t care if you publish the SSH keys then?
They’ve probably rotated the keys since they were notified of the security breach.
But yes, companies that act this way undermine the resolve to disclose their security vulnerabilities.
Ssh keys to what? If the key is used for user operations, not internal then there’s no security breach here other than deobfuscation.
Guess they’ll have to publish them to find out
Time to try and convince it to set up a reverse SSH tunnel
Soo, was that incompetence, negligence or misled belief, trust?
Yes




