yaala retweetledi
yaala
211 posts

yaala retweetledi

Account Takeover in Facebook mobile app due to usage of cryptographically unsecure random number generator and XSS in Facebook JS SDK ($66,000)
ysamm.com/uncategorized/…
English
yaala retweetledi

“Escalating Impact: Full Account Takeover in Microsoft via XSS in Login Flow” by Asem Eleraky melotover.medium.com/escalating-imp…

English

@sho3hit @jobertabma Maybe you are testing with a report that doesn’t have a summary ??
English

@jobertabma I did the same thing in the month of January, and it wasn’t there. I have logs too. So how did it come up in February?
English

This was a great find and had a super interesting root cause: hackerone.com/reports/3000510
English
yaala retweetledi

Detect the NextJS middleware bypass directly in Burp Suite with this BCheck from @eternalky_u
gist.github.com/fourcube/45a78…
English

I'm honestly still in disbelief... grateful to receive a $100k bounty from @meta. Feels surreal. Sharing this to show that with time and dedication, it's possible. This was my first and only submission to Facebook - something I've been chasing for a decade! 🙏 Big thank you to @metabugbounty!

English
yaala retweetledi

I recently developed and posted about a technique called "First sequence sync", expanding @albinowax's single packet attack.
This technique allowed me to send 10,000 requests in 166ms, which breaks the packet size limitation of the single packet attack.
flatt.tech/research/posts…
English

HackerOne disclosed a bug submitted by @sagarbhavar: hackerone.com/reports/815085 - Bounty: $3,750 #hackerone #bugbounty

English
yaala retweetledi

According to the media, it is a "war crime" to bomb military targets in #Ukraine, but it is perfectly fine to bomb civilians in #Gaza.
If the media won’t say it, I will.
Israel is a TERRORIST state‼️
#ZionistTerror #Gaza_Genocide #IsraelGazaWar #GazaAttack #PalestineGenocide
English
yaala retweetledi

Solved! Chrome debugger was enabled and allowed access via http://localhost:9222/json. This allowed exfiltrating data from other users whosoever was hitting this headless chrome browser - more info here - chromedevtools.github.io/devtools-proto…
Thanks everyone for the tips :)
Bhavuk Jain@bhavukjain1
Have a full read SSRF via headless chrome, can access GCP metadata but cannot escalate using the creds (highly restricted). Tried finding any internal/external subdomains (reachable via specific IP addresses) but cannot find any. Any thoughts on how this can be escalated?
English

When you hunt on a shopping website try this trick:
Add these items to your cart
Item 1: 50$
Item 2: 49$
Change the quantity of Item 2 to -1 (negative amount)
Subtotal: 1$
With this trick you can buy Item 1 for 1$
#bugbountytips #bugbountytip #bugbounty
English

Sometimes going back to old old versions is not a waste of time.
A bug was found in 2022.
Title : from username all contact points associated with that account were disclosed in the invalid login error message
youtu.be/9-FuYzhBGvo

YouTube
English

Delete any video/Reel
Facebook paid >10000$
Bassem M bazzoun@bassemmbazzoun
A reward of 11,250$ from Facebook after reporting a security vulnerability that could allow me to delete any video or reel posted on the platform. bugreader.com/social/write-u… #cybersecuriy #BugBounty #hackers #penetrationtesting #facebook #meta
English





