001 The archive

Field Notes.

Technique breakdowns and disclosure notes drawn from active research - written up while the details still matter, and published only when it's responsible to do so.

Google 27 Apr 2026

[Chromium] Drag and drop a Data URI to spoof a dialog

Back in June, I came across some interesting behaviour with Google Chrome. If you drag and drop a Data URI (image or hyperlink) into a new tab and this…

15 min
Microsoft 20 Feb 2026

[Outlook] How an attacker could modify your sent items!

In the world of business disputes, the "Sent Items" folder is often treated as the source of truth. We implicitly trust that what sits in that folder is an…

7 min
Meta 17 Jul 2025

Crafting Malicious Facebook Ads via Instant Experiences

Everyone who uses Facebook has seen them: slick, fast-loading ads that open up into a full-screen experience without ever leaving the app. These are called…

11 min
Meta 05 Jun 2025

Bypass client-side validation on a Facebook Page Contact Form

The "Action Button" feature found against a Facebook page has an option to create a Contact Form. This Contact Form allows a page to collect pre-defined…

4 min
Microsoft 25 May 2025

XSS to RCE - Xbox Device Portal

The Xbox Device Portal is an invaluable tool for developers, offering remote access to an Xbox console in developer mode via a web browser. It allows for…

9 min
Meta 06 Jul 2022

Bountycon 2022 - Android Trinity PWN

Whilst working on the BountyCon 2022 CTF , I spent the majority of the time focusing on the Android Trinity challenge. This was one of two PWN challenges…

3 min
30 Mar 2022

Disclosing BCC Recipients of an email

This post will cover an interesting logic flaw found in a private bug bounty program. Whilst the name of this company will be known as [REDACTED], the…

5 min
Meta 02 Feb 2022

Abusing Facebooks Call To Action to launch internal deeplinks

Ever noticed that big blue button on the top of every Facebook page? This feature, known as Call to action or CTA is designed for user engagement and…

8 min
Meta 20 Jan 2022

Open redirects are not dead! Or are they?

Over the last few years doing bug bounties, it's becoming more and more common for companies to reject reports about Open Redirects . Once upon a time we…

5 min
Microsoft 18 Oct 2021

Bypass Microsoft Teams Tenancy Permission - Edit Sent Messages

Back in December 2019 I reported a Microsoft Teams Tenancy Permission bypass that allowed a user to modify their sent messages despite the global…

8 min
27 Jun 2021

Abusing corporate URL shorteners

URL shorteners are great! They allows users to turn a 200 character url into something substansially less. It's ideal for those situations where you are…

6 min
Meta 02 Feb 2021

Bypassing locked profile restrictions on Facebook

Facebook allows certain users to set their Facebook profile to be "locked". This means other users are not able to view their full profile picture / cover…

3 min

002 Engagements

Enjoying the notes? See the work live.

Every writeup here came out of real engagements and bounty programmes. Book an assessment and you get findings of your own - thoroughly tested, clearly written, honestly priced.