001 The archive
Field Notes.
Technique breakdowns and disclosure notes drawn from active research - written up while the details still matter, and published only when it's responsible to do so.
[Chromium] Drag and drop a Data URI to spoof a dialog
Back in June, I came across some interesting behaviour with Google Chrome. If you drag and drop a Data URI (image or hyperlink) into a new tab and this…
[Outlook] How an attacker could modify your sent items!
In the world of business disputes, the "Sent Items" folder is often treated as the source of truth. We implicitly trust that what sits in that folder is an…
Crafting Malicious Facebook Ads via Instant Experiences
Everyone who uses Facebook has seen them: slick, fast-loading ads that open up into a full-screen experience without ever leaving the app. These are called…
Bypass client-side validation on a Facebook Page Contact Form
The "Action Button" feature found against a Facebook page has an option to create a Contact Form. This Contact Form allows a page to collect pre-defined…
XSS to RCE - Xbox Device Portal
The Xbox Device Portal is an invaluable tool for developers, offering remote access to an Xbox console in developer mode via a web browser. It allows for…
Bountycon 2022 - Android Trinity PWN
Whilst working on the BountyCon 2022 CTF , I spent the majority of the time focusing on the Android Trinity challenge. This was one of two PWN challenges…
Disclosing BCC Recipients of an email
This post will cover an interesting logic flaw found in a private bug bounty program. Whilst the name of this company will be known as [REDACTED], the…
Abusing Facebooks Call To Action to launch internal deeplinks
Ever noticed that big blue button on the top of every Facebook page? This feature, known as Call to action or CTA is designed for user engagement and…
Open redirects are not dead! Or are they?
Over the last few years doing bug bounties, it's becoming more and more common for companies to reject reports about Open Redirects . Once upon a time we…
Bypass Microsoft Teams Tenancy Permission - Edit Sent Messages
Back in December 2019 I reported a Microsoft Teams Tenancy Permission bypass that allowed a user to modify their sent messages despite the global…
Abusing corporate URL shorteners
URL shorteners are great! They allows users to turn a 200 character url into something substansially less. It's ideal for those situations where you are…
Bypassing locked profile restrictions on Facebook
Facebook allows certain users to set their Facebook profile to be "locked". This means other users are not able to view their full profile picture / cover…
002 Engagements
Enjoying the notes? See the work live.
Every writeup here came out of real engagements and bounty programmes. Book an assessment and you get findings of your own - thoroughly tested, clearly written, honestly priced.