Latest Posts
Abusing Facebooks Call To Action to launch internal deeplinks
Ever noticed that big blue button on the top of every Facebook page? This feature, known as Call to action or CTA is designed for user...
Open redirects are not dead! Or are they?
Over the last few years doing bug bounties, it's becoming more and more common for companies to reject reports about Open Redirects. Once upon a...
Bypass Microsoft Teams Tenancy Permission - Edit Sent Messages
Back in December 2019 I reported a Microsoft Teams Tenancy Permission bypass that allowed a user to modify...
Abusing corporate URL shorteners
URL shorteners are great! They allows users to turn a 200 character url into something substansially less. It's ideal for those...
Bypassing locked profile restrictions on Facebook
Facebook allows certain users to set their Facebook profile to be "locked". This means other users are not able to view their full profile...
Launching internal & non-exported deeplinks on Facebook
The report was submitted as a collaboration between myself and Rahul Kankrale. The split was 70% Ash & 30% Rahul. It was possible...