Stephen Sclafani Profile
Stephen Sclafani

@Stephen

3,806
Followers
264
Following
20
Media
863
Statuses

Security Researcher

Joined March 2007
Don't wanna be here? Send us removal request.
Pinned Tweet
@Stephen
Stephen Sclafani
10 years
Hacking Facebook’s Legacy API, Part 1: Making Calls on Behalf of Any User ($20,000 bounty) http://t.co/ibrHHcm4KK
38
70
97
@Stephen
Stephen Sclafani
7 years
Going to post a writeup of this soon (I promise).
Tweet media one
12
37
179
@Stephen
Stephen Sclafani
8 years
. @phwd I'll try to stop being lazy and do a writeup on this sometime soon.
Tweet media one
3
13
44
@Stephen
Stephen Sclafani
7 years
No problem getting an iPhone X through Verizon's site.
9
10
29
@Stephen
Stephen Sclafani
10 years
I probably should write a blog post on this Facebook bug bounty from December. #lazy http://t.co/8pMyOezrQh
Tweet media one
6
13
29
@Stephen
Stephen Sclafani
9 years
Finally heard from United that my bounty submission was accepted (500,000 miles). cc: @NealPoole http://t.co/HJtIZMQTVI
Tweet media one
3
5
19
@Stephen
Stephen Sclafani
10 years
Hacking Facebook’s Legacy API, Part 2: Stealing User Sessions http://t.co/Drk5po5b7W
0
18
19
@Stephen
Stephen Sclafani
7 years
Got to hold on posting the writeup for another week while Facebook fixes some related issues.
2
1
15
@Stephen
Stephen Sclafani
7 years
@JosipFranjkovic Five of my reports were Oculus related but I missed this one. Nice find ;)
1
0
11
@Stephen
Stephen Sclafani
11 years
Obtaining The Primary Email Address Of Any Facebook User http://t.co/HoeVOTkDwM
0
16
9
@Stephen
Stephen Sclafani
9 years
Anti-ride-sharing ad from a local black car service: three guys in a bar, one gets a ping from an Uber-like app, stumbles out drunk.
0
12
1
@Stephen
Stephen Sclafani
9 years
The new Facebook HQ has an office that's also a ball pit. http://t.co/RKDP1xIuaw
Tweet media one
1
3
7
@Stephen
Stephen Sclafani
10 years
"After reviewing the bug details you have provided, our security team has determined that you are eligible to receive a payout of $6000."
0
1
6
@Stephen
Stephen Sclafani
9 years
Reported a couple bugs to the Western Union bounty program. Waiting on responses. Haven't bothered with other programs than FB in a while.
0
5
5
@Stephen
Stephen Sclafani
10 years
Back in 2008 I found a XSS in Facebook's ads themselves. I wonder how much they would reward for that today (a lot).
0
1
4
@Stephen
Stephen Sclafani
10 years
When a company launches a bounty program and multiple critical bugs are reported day one it says a lot about the companies without programs.
1
0
5
@Stephen
Stephen Sclafani
10 years
So far two of my reports to Microsoft have qualified for bounties. Waiting on amounts.
1
0
4
@Stephen
Stephen Sclafani
7 years
@prakharprasad @Nirgoldshlager reading Nir's OAuth writeups is what inspired me to start looking for these types of issues.👍
0
0
4
@Stephen
Stephen Sclafani
10 years
Should have bought that snow blower... http://t.co/LE5ZL2McPd
Tweet media one
0
8
4
@Stephen
Stephen Sclafani
10 years
On top
0
0
4
@Stephen
Stephen Sclafani
10 years
@Bitquark Nice. Microsoft pays well for XSS, $2,500 for one on Yammer (reflected). One on http://t.co/79szd38pWL should pay more.
2
0
4
@Stephen
Stephen Sclafani
10 years
0
0
3
@Stephen
Stephen Sclafani
10 years
XSS question: Can you break out of a function without using {}? cc: @avlidienbrunn @0x6D6172696F @orenhafif
2
0
2
@Stephen
Stephen Sclafani
10 years
@Stephen This was my second largest bounty ever (the largest being http://t.co/zT2riFtPQR).
0
0
3
@Stephen
Stephen Sclafani
8 years
@ericflo There's a personalized recommended feed, usually shows good suggestions for me:
1
0
2
@Stephen
Stephen Sclafani
10 years
Interesting that Twitter displays your join date on the new profile. Other than bragging rights for early adopters, is that useful info?
0
0
3
@Stephen
Stephen Sclafani
10 years
I alerted Verizon in Oct. to broken/missing auth (was poss. to reset any user's pass). Fixed, but others still exist http://t.co/49eQDrYAno
0
2
2
@Stephen
Stephen Sclafani
8 years
@samhouston Reckful is right now
1
0
3
@Stephen
Stephen Sclafani
6 years
1
0
2
@Stephen
Stephen Sclafani
10 years
. @fin1te You sniped me this time last year. It's not going to happen again :)
0
0
1
@Stephen
Stephen Sclafani
9 years
@fmanjoo Seems obvious that it will be an option.
0
0
2
@Stephen
Stephen Sclafani
8 years
@MikeIsaac Old: The Omen (1976 version) New: Babadook
0
0
2
@Stephen
Stephen Sclafani
9 years
@thegrugq @homakov Probably only few people making anything close to $30k/month from web bounties.
0
0
1
@Stephen
Stephen Sclafani
13 years
"Kimble was arrested yesterday, his panic-room door busted down by officials, who found the hacker clinging to a sawed-off shotgun."
0
0
2
@Stephen
Stephen Sclafani
9 years
@fmanjoo I'm not sure why people think that Twitter is going to replace the chronological timeline with the algorithmic timeline.
1
0
2
@Stephen
Stephen Sclafani
8 years
0
0
2
@Stephen
Stephen Sclafani
10 years
0
0
2
@Stephen
Stephen Sclafani
10 years
@kevinroose This video does a good job explaining why
0
1
2
@Stephen
Stephen Sclafani
9 years
A lot of awesome moments in The Force Awakens
1
8
1
@Stephen
Stephen Sclafani
10 years
No problems preordering an iPhone 6+ through Verizon.
0
0
1
@Stephen
Stephen Sclafani
14 years
@Scobleizer It looks like Meebo picked the wrong day to launch their checkin feature. Everybody is talking about Path.
0
2
2
@Stephen
Stephen Sclafani
10 years
@nikcub Here's a list of the top retweets if you're curious: http://t.co/nI5WBGFh2E (lots of celeb tweets with six-figures).
1
0
2
@Stephen
Stephen Sclafani
10 years
@fmanjoo Because many of those followers aren't seeing your posts due to Facebook's news feed algorithm.
0
0
2
@Stephen
Stephen Sclafani
8 years
@samhouston summit is trying to also but it looks like he's having connection issues
1
0
2
@Stephen
Stephen Sclafani
10 years
@ErrataRob Yeah, surge areas are shown on their map http://t.co/hQaqlDPgVw
Tweet media one
0
1
2
@Stephen
Stephen Sclafani
8 years
@samhouston Xbox Live is down.
1
0
2
@Stephen
Stephen Sclafani
11 years
@stevekovach @CalebGarling Probably the use of the word "snoots" gave you away.
0
0
1
@Stephen
Stephen Sclafani
9 years
@homakov @thegrugq Yeah, the end game for bounties is for someone to give you a full time job.
3
0
2
@Stephen
Stephen Sclafani
10 years
. @ErrataRob Not from Sydney, but this is what drivers see when pinged to accept a fare during a surge. http://t.co/ewjMghKA8j
Tweet media one
1
0
2
@Stephen
Stephen Sclafani
10 years
@Agarri_FR @Zigoo0 Facebook and Google are the only two programs that I've used that reliably pay 4/5 figure bounties for serious issues.
0
0
2
@Stephen
Stephen Sclafani
10 years
@isaach @ladymisskate Owned by a Lamborghini dealer in Miami. He rents it out. Someone's been driving it around SF the last couple weeks.
0
0
1
@Stephen
Stephen Sclafani
15 years
@SlideShare_Dan I sent you an email.
0
0
1
@Stephen
Stephen Sclafani
10 years
@homakov I use Burp. If you install its CA certificate in your browser you wont get warnings or broken requests. http://t.co/DZrTduqf2R
0
0
1
@Stephen
Stephen Sclafani
13 years
Google+ is a pretty good social network for people to talk about Google+ on.
1
0
1
@Stephen
Stephen Sclafani
10 years
@arrington Probably a good buying opportunity.
0
0
0
@Stephen
Stephen Sclafani
11 years
@parislemon It premiered during the Colts-Patriots game. I wonder how much a 60-second commercial during the playoffs costs.
0
0
1
@Stephen
Stephen Sclafani
10 years
@homakov @agelastic Don't link to your HN submissions from Twitter or from your blog. Direct votes actually count against you.
1
0
1
@Stephen
Stephen Sclafani
8 years
@LIRIK It's always high noon somewhere.
0
0
1
@Stephen
Stephen Sclafani
15 years
0
0
1
@Stephen
Stephen Sclafani
12 years
@theharmonyguy There's some good answers on Quora regarding SF.
0
0
0
@Stephen
Stephen Sclafani
10 years
@homakov @agelastic More explanation:
0
0
1
@Stephen
Stephen Sclafani
10 years
@PaulWebSec You shouldn't. Along with Google's, Facebook's is one of the best run programs. They have the highest payouts as well, IMO.
0
0
1
@Stephen
Stephen Sclafani
15 years
@arrington You should give The Wire more of a chance. Watching just the first episode of any show rarely gives one the feel of the show.
0
0
1
@Stephen
Stephen Sclafani
13 years
Finally getting around to playing Tales of Monkey Island
0
0
1
@Stephen
Stephen Sclafani
14 years
@Jason I'm enjoying TWiVC. Funding announcements tend to read like press releases. Good to hear some honest opinions.
0
0
1
@Stephen
Stephen Sclafani
11 years
It's looking like Star Trek 2009 ($75m) will have had a better opening weekend than Into Darkness ($70.5m).
0
0
1
@Stephen
Stephen Sclafani
9 years
@NealPoole Waiting on one myself. Reported around the same time as @psifertex . Hope to hear something soon.
1
0
1
@Stephen
Stephen Sclafani
9 years
0
0
1
@Stephen
Stephen Sclafani
9 years
@samhouston Those of us on the East Coast are a bit less excited thanks to the coming blizzard :)
0
0
1
@Stephen
Stephen Sclafani
11 years
@dozba You'd probably find this interesting: http://t.co/BOdMkEYyjf
0
0
1
@Stephen
Stephen Sclafani
15 years
No one was injured in the explosion or fire. What the cause was I don't know.
0
0
1
@Stephen
Stephen Sclafani
9 years
@fransrosen Yes, you could. The penalty is added even if you aren't the submitter.
1
0
1
@Stephen
Stephen Sclafani
11 years
Pacific Rim was a good movie about giant robots fighting giant monsters interspersed with humans speaking bad dialogue.
0
2
1
@Stephen
Stephen Sclafani
9 years
@McGrewSecurity @SteveD3 It doesn't make any sense for RSA to use this flow over the normal OAuth flow.
1
2
1
@Stephen
Stephen Sclafani
8 years
@NealPoole @mmihaljevic The tax is a killer unless you fly a lot. There's some tricks to get around the expiration:
1
0
1
@Stephen
Stephen Sclafani
10 years
@nikcub When Stephen Hawking made some comments about religion a while ago I got a flood of angry replies.
1
0
1
@Stephen
Stephen Sclafani
11 years
Just watched all 15 episodes of season 5 of Breaking Bad in one sitting. Couldn't wait another week.
0
0
1
@Stephen
Stephen Sclafani
9 years
@maxbulger @chrismaddern Probably a significant amount. Periscope is already in the top 100, Meerkat never cracked the top 150.
0
0
1
@Stephen
Stephen Sclafani
10 years
@pmarca @fmanjoo They already do that, at least when the tweet is made from the web: http://t.co/haHUJO6959
0
0
1
@Stephen
Stephen Sclafani
13 years
@Jason Features don't make a social network social, people do.
0
0
0
@Stephen
Stephen Sclafani
10 years
@parislemon $2 billion is definitely going to look like a steal in the future.
0
0
1
@Stephen
Stephen Sclafani
11 years
Always been curious what the bounty would be for a Facebook account takeover w/o user interaction. Answer: $20,000 http://t.co/bh0IWhE3xy
1
1
1
@Stephen
Stephen Sclafani
15 years
@CodyBrown Meaning Twitter will only assume that your tweets relate to your location when you tell it so.
0
0
1
@Stephen
Stephen Sclafani
13 years
RT @BenjaminLyons $50,000 safety bet! Best superbowl!! http://t.co/lpD8d0uL
Tweet media one
0
0
1
@Stephen
Stephen Sclafani
14 years
Schmidt got Zuckerpunched
0
0
1
@Stephen
Stephen Sclafani
9 years
0
0
1
@Stephen
Stephen Sclafani
12 years
Smart acquisition by Facebook. They couldn't allow someone else to get a foothold in photo sharing. Esp. in mobile. http://t.co/e3mBP0Er
1
0
1
@Stephen
Stephen Sclafani
11 years
Given that it's being billed as a sequel to Man of Steel, 'Superman and Batman' would seem to be the correct one.
0
1
1
@Stephen
Stephen Sclafani
9 years
@jeremiahg @psifertex In United's ToS: "Bugs or potential Bugs you discover may not at any time be disclosed publicly or to a third-party."
3
1
1