001 The archive
Field Notes.
Technique breakdowns and disclosure notes drawn from active research - written up while the details still matter, and published only when it's responsible to do so.
Crafting Malicious Facebook Ads via Instant Experiences
Everyone who uses Facebook has seen them: slick, fast-loading ads that open up into a full-screen experience without ever leaving the app. These are called…
Bypass client-side validation on a Facebook Page Contact Form
The "Action Button" feature found against a Facebook page has an option to create a Contact Form. This Contact Form allows a page to collect pre-defined…
Bountycon 2022 - Android Trinity PWN
Whilst working on the BountyCon 2022 CTF , I spent the majority of the time focusing on the Android Trinity challenge. This was one of two PWN challenges…
Abusing Facebooks Call To Action to launch internal deeplinks
Ever noticed that big blue button on the top of every Facebook page? This feature, known as Call to action or CTA is designed for user engagement and…
Open redirects are not dead! Or are they?
Over the last few years doing bug bounties, it's becoming more and more common for companies to reject reports about Open Redirects . Once upon a time we…
Bypassing locked profile restrictions on Facebook
Facebook allows certain users to set their Facebook profile to be "locked". This means other users are not able to view their full profile picture / cover…
Launching internal & non-exported deeplinks on Facebook
The report was submitted as a collaboration between myself and Rahul Kankrale . The split was 70% Ash & 30% Rahul. Summary It was possible to override the…
Ability To Backdoor Facebook For Android
I found a security vulnerability in Facebook for Android which made it possible to backdoor the application. By abusing a development deeplink it was…
Downloading any file via Facebook for Android
.single-post-details blockquote{filter:none!important} Summary The Facebook android app utilises deeplinks throughout the whole application. I stumbled…
Breaking The Facebook For Android Application
Whilst working on the Facebook Bug Bounty Program in June 2018 we had identified an issue with the webview component used in the Facebook for Android…
002 Engagements
Enjoying the notes? See the work live.
Every writeup here came out of real engagements and bounty programmes. Book an assessment and you get findings of your own - thoroughly tested, clearly written, honestly priced.