/Meta-Owned-IT-Assets

Curated list of Meta (formerly Facebook) owned IT assets

Interesting IT Assets Owned by Meta (Facebook)

Meta Platforms, Inc., formerly known as Facebook, Inc., is a highly valuable company and a significant player in the bug bounty domain. According to an article, Meta has paid out over $16 million in bug bounties since 2011. Due to its popularity and reputation, Meta has become a prime target for security researchers and bug bounty hunters. As a result, it has become quite challenging to find even relatively simple bugs mentioned in standard security frameworks such as OWASP.

Based on my experience and analysis over the past decade, I have observed that most of the bugs rewarded by Facebook are client-side or business logic vulnerabilities. These include MFA bypass, IDOR via GraphQL, CSRF, DOM XSS, CSP bypass, open redirect, privacy issues, rate limiting, logic flaws, authorization flaws, OAuth/SSO misconfigurations, and information disclosure, among others. However, server-side high/critical vulnerabilities such as SQL/LDAP/XPath/XML injection, ELI, SSTI, code/OS command injection, insecure deserialization, file path traversal (LFI/AFR/RFI), SSRF, SSI, buffer overflow/memory leak, SMTP/HTTP header injection (also known as "CRLF"), directory listing, or missing error handling leading to source code/secret leaks are rarely found. The credit goes to Facebook's strong core architecture and secure logic implementation using the Hack language on top of the HHVM server. As a result, it is nearly impossible to obtain a reverse or bind root shell of the facebook.com server.

Similar to other companies, Facebook does not rely solely on in-house developed software/applications. It also uses third-party applications and hosts them on some subdomains. As these third-party software applications require different server configurations, it is possible for server-side vulnerabilities to arise. The question then becomes: How do we identify such subdomains and find these vulnerabilities? The answer lies in reconnaissance (recon).

The term "recon" originates from its military usage to describe an information-gathering mission. Reconnaissance can be both fun and time-consuming. Therefore, I would like to share a list of interesting IT assets owned by Meta (formerly Facebook) with the security research community. I have identified all these assets using various tools and platforms, including:

  • Shodan: An internet-connected device search engine.
  • Hurricane Electric BGP Toolkit: A network information and IP address lookup tool.
  • DNSDumpster: A DNS (Domain Name System) information gathering tool.
  • Censys: An internet-wide search engine for discovering devices and networks.
  • BinaryEdge: An internet scanning and threat intelligence platform.
  • crt.sh: A certificate search and monitoring tool.
  • SubdomainFinder: A subdomain enumeration and discovery tool.
  • YouGetSignal: A web server hosting multiple websites detection tool.
  • Google Dork: Customized search queries using Google's search operators.
  • Other open-source programs/tools/frameworks for IT asset discovery.

This comprehensive list includes relevant details such as the applications running on these assets. For proprietary applications, information about the developer is provided, while open-source applications include links to their source code. These assets were identified during my security research, and I believe that sharing them will save time for testers in discovering subdomains and identifying the software in use.

It is important to note that I am not promoting or encouraging anyone to access or test any of the listed assets without proper authorization. Maintain ethical practices and follow authorized access when conducting any security research. Before accessing or testing any of the assets mentioned, please read and comply with the terms, rules, and research scope specified on https://www.facebook.com/whitehat and https://www.facebook.com/security/advisories/Vulnerability-Disclosure-Policy

List of Meta-Owned IT Assets

  1. BeyondTrust Remote Support Software: It allows support organizations to access and assist remote computers and mobile devices. The following Facebook assets host this software:

    Additionally, some interesting technical guidelines and product documentation for BeyondTrust Remote Support Software can be found publicly at rs-admin.pdf.

  2. Excalidraw: Excalidraw is a virtual collaborative whiteboard tool that allows users to easily sketch diagrams with a hand-drawn feel. It is an open-source tool available on GitHub at excalidraw/excalidraw. The following Facebook assets host Excalidraw:

  3. MuleSoft's APIkit: APIkit is a tool developed by MuleSoft for building Mule REST or SOAP APIs. It is an open-source project available on GitHub at mulesoft/apikit. The following Facebook assets expose APIkit Console:

  4. Cortex DAM: Cortex DAM is a digital asset management platform developed by Orange Logic. It is hosted on the following Facebook-owned domains:

  5. F5 BIG-IP Access Policy Manager: The F5 BIG-IP Access Policy Manager (APM) is a solution that enables users or organizations to utilize single sign-on (SSO) for accessing applications from anywhere. You can find the manual, supplemental documents, and release notes for BIG-IP APM here. For other interesting technical documents related to F5 products, you can use the following Google dork: site:f5.com "my.policy" ext:pdf. Subdomains hosting BIG-IP APM:

  6. Verdaccio: Verdaccio is a lightweight Node.js private proxy registry. It is an open-source project available on GitHub at verdaccio/verdaccio. Facebook assets hosting Verdaccio:

  7. TAP - PROD: TAP (possibly short for "The Authentication Provider") appears to be an identity server, but further details are unknown. The unmaintained and archived code related to the identity server is available as an open-source project on GitHub at IdentityServer. Subdomains associated with TAP - PROD:

  8. Neurons for MDM: Neurons for MDM (Mobile Device Management) is a cloud-based platform for modern device management developed by Ivanti (formerly MobileIron). You can find relevant technical documents and information about Neurons for MDM online, such as the Low User Impact Migration Portal 11 Guide, Ivanti Neurons for MDM (N-MDM) Migration Resource Toolkit, and MobileIron Migration Portal User Guide - Product Documentation. Facebook assets related to Neurons for MDM:

  9. Velociraptor: Velociraptor is an advanced digital forensic and incident response tool used for collecting host-based state information using the Velociraptor Query Language (VQL) queries. It is an open-source project available on GitHub at Velocidex/velociraptor. Facebook asset hosting Velociraptor:

  10. Zendesk: Zendesk is a customer support platform. Facebook asset hosting Zendesk:

  11. WordPress: WordPress is a popular content management system. Facebook asset hosting WordPress:

  12. Cisco ASA VPN: Cisco ASA VPN is a virtual private network solution. The following Facebook assets host this software:

If you're interested in learning about subdomain naming conventions used by Facebook, you can read more about it here.

  1. Phabricator: Phabricator is an open-source software development collaboration platform. Available on GitHub at phacility/phabricator. Facebook assets related to Phabricator:

  2. Facebook Employee Login:

  3. Open Source Software Repositories:

  4. Google Dorks: (Note: Google search results may vary based on locality and ISP.)

  5. URL shortening service: Shortened URL service provided by Facebook.

  6. Critical assets: These in-house developed assets are hosting user-sensitive data:

  7. Microsoft Exchange Autodiscover:

  8. Other Interesting Domains and Endpoints:

Other Information

Please note that at the time of writing, all the URLs mentioned in the list are accessible. However, keep in mind that the availability of these URLs may change over time. I will do my best to update if any URLs become inaccessible.

Contribution

If you know any interesting assets/URLs that are dynamic in nature, host open-source or third-party applications, or if you know of applications developed by Meta itself, please feel free to submit a pull request. Additionally, individuals can share PoC they consider important or security-sensitive, even if they haven't been accepted by Facebook as bugs.