001 The archive
Field Notes.
Technique breakdowns and disclosure notes drawn from active research - written up while the details still matter, and published only when it's responsible to do so.
Launching internal & non-exported deeplinks on Facebook
The report was submitted as a collaboration between myself and Rahul Kankrale . The split was 70% Ash & 30% Rahul. Summary It was possible to override the…
ShazLocate!<br> Abusing CVE-2019-8791 & CVE-2019-8792
I found a vulnerability in the popular Shazam application that allowed an attacker to steal the precise location of a user simply by clicking a link! This…
Ability To Backdoor Facebook For Android
I found a security vulnerability in Facebook for Android which made it possible to backdoor the application. By abusing a development deeplink it was…
Downloading any file via Facebook for Android
.single-post-details blockquote{filter:none!important} Summary The Facebook android app utilises deeplinks throughout the whole application. I stumbled…
Breaking The Facebook For Android Application
Whilst working on the Facebook Bug Bounty Program in June 2018 we had identified an issue with the webview component used in the Facebook for Android…
002 Engagements
Enjoying the notes? See the work live.
Every writeup here came out of real engagements and bounty programmes. Book an assessment and you get findings of your own - thoroughly tested, clearly written, honestly priced.