Latest Posts
Bypass Microsoft Teams Tenancy Permission - Edit Sent Messages
Back in December 2019 I reported a Microsoft Teams Tenancy Permission bypass that allowed a user to modify...
Abusing corporate URL shorteners
URL shorteners are great! They allows users to turn a 200 character url into something substansially less. It's ideal for those...
Bypassing locked profile restrictions on Facebook
Facebook allows certain users to set their Facebook profile to be "locked". This means other users are not able to view their full profile...
Launching internal & non-exported deeplinks on Facebook
The report was submitted as a collaboration between myself and Rahul Kankrale. The split was 70% Ash & 30% Rahul. It was possible...
ShazLocate!
Abusing CVE-2019-8791 & CVE-2019-8792
I found a vulnerability in the popular Shazam application that allowed an attacker to steal the precise location of a user simply by clicking a...
Ability To Backdoor Facebook For Android
I found a security vulnerability in Facebook for Android which made it possible to backdoor the application. By abusing a development...