Forwarded from Android Security & Malware
CVE-2019-8646 is a vulnerability in iMessage that can allow memory to be leaked and files to be read remotely from a device.
Demo: https://youtu.be/br2xCvtVFn4
Research: https://googleprojectzero.blogspot.com/2019/08/the-many-possibilities-of-cve-2019-8646.html
Demo: https://youtu.be/br2xCvtVFn4
Research: https://googleprojectzero.blogspot.com/2019/08/the-many-possibilities-of-cve-2019-8646.html
YouTube
iPhone Remote File Read Demo
A demo of CVE-2019-8646, retrieving an image from a remote device's messages
Finding Hidden API Keys & How to use them
https://medium.com/@sumitcfe/finding-hidden-api-keys-how-to-use-them-11b1e5d0f01d
https://medium.com/@sumitcfe/finding-hidden-api-keys-how-to-use-them-11b1e5d0f01d
Medium
Finding Hidden API Keys & How to use them
Hi Everyone,
Toolkit to detect and keep track on Blind XSS, XXE & SSRF
https://github.com/SpiderMate/B-XSSRF
https://github.com/SpiderMate/B-XSSRF
GitHub
GitHub - SpiderMate/B-XSSRF: Toolkit to detect and keep track on Blind XSS, XXE & SSRF
Toolkit to detect and keep track on Blind XSS, XXE & SSRF - SpiderMate/B-XSSRF
[iOS Application Security] Jailbreak 12.4 and SSL pinning bypass | How to set up your iOS Testing Lab
https://medium.com/@yogendra_h1/ios-application-security-jailbreak-12-4-5e3fc0dc0726
https://medium.com/@yogendra_h1/ios-application-security-jailbreak-12-4-5e3fc0dc0726
Medium
[iOS Application Security] Jailbreak 12.4
Hello Everyone — Long time no see!
Stack overflow in XML Parsing
https://hackerone.com/reports/480883
https://hackerone.com/reports/480883
HackerOne
Notepad++ disclosed on HackerOne: Stack overflow in XML Parsing
**Summary:**
A stack buffer overflow vulnerability has been detected in XML parsing functionality on Notepad++.
That's due to the fact that _invisibleEditView.getText function doesn't check...
A stack buffer overflow vulnerability has been detected in XML parsing functionality on Notepad++.
That's due to the fact that _invisibleEditView.getText function doesn't check...
BUG BOUNTY: BYPASSING A CRAPPY WAF TO EXPLOIT A BLIND SQL INJECTION
https://robinverton.de/blog/2019/08/25/bug-bounty-bypassing-a-crappy-waf-to-exploit-a-blind-sql-injection/
https://robinverton.de/blog/2019/08/25/bug-bounty-bypassing-a-crappy-waf-to-exploit-a-blind-sql-injection/
How I made my first $$$ from finding a bug in Facebook
https://medium.com/@aayushpokhrel/how-i-made-my-first-from-finding-a-bug-in-facebook-da3b11e550f0
https://medium.com/@aayushpokhrel/how-i-made-my-first-from-finding-a-bug-in-facebook-da3b11e550f0
Medium
How I made my first $$$ from finding a bug in Facebook
One day i decided to search bug in Facebook and i choose Facebook lite application to find bug and after some hours i got one small issues…
jsonp is a Burp Extension which attempts to reveal JSONP functionality behind JSON endpoints. This could help reveal cross-site script inclusion vulnerabilities or aid in bypassing content security policies.
https://github.com/kapytein/jsonp
https://github.com/kapytein/jsonp
GitHub
GitHub - kapytein/jsonp: jsonp is a Burp Extension which attempts to reveal JSONP functionality behind JSON endpoints.
jsonp is a Burp Extension which attempts to reveal JSONP functionality behind JSON endpoints. - kapytein/jsonp
Hail Frida!! The Universal SSL pinning bypass for Android applications
https://medium.com/@ved_wayal/hail-frida-the-universal-ssl-pinning-bypass-for-android-e9e1d733d29
https://medium.com/@ved_wayal/hail-frida-the-universal-ssl-pinning-bypass-for-android-e9e1d733d29
Medium
Hail Frida!! The Universal SSL pinning bypass for Android applications
In this article, I’ll explain how to bypass SSL pinning of any android application using frida framework.
How to look for JS files Vulnerability for fun and profit?
https://medium.com/@Skylinearafat/how-to-look-for-js-files-vulnerability-for-fun-and-profit-78bfdfbd6731
https://medium.com/@Skylinearafat/how-to-look-for-js-files-vulnerability-for-fun-and-profit-78bfdfbd6731
Medium
How to look for JS files Vulnerability for fun and profit?
Hey Folks, It’s been a while I was away from Bug Hunting. These days I got some chances to focus on hunting again I decided to hunt on…
Access Projects And create projects in gitlab pre production server
https://hackerone.com/reports/540711
https://hackerone.com/reports/540711
HackerOne
GitLab disclosed on HackerOne: Access Projects And create projects...
### Steps to reproduce
Go to https://pre.gitlab.com
Here any one can register and can view the pre production projects of gitlab developers.
I have registered in...
Go to https://pre.gitlab.com
Here any one can register and can view the pre production projects of gitlab developers.
I have registered in...
Opening up a Universal XSS vulnerability in Microsoft Edge
https://hackerone.com/reports/463915
https://hackerone.com/reports/463915
HackerOne
Kaspersky disclosed on HackerOne: URL Advisor component in KIS...
**Summary**
In Microsoft Edge, URL Advisor UI is served as first-party content on every domain. So the XSS vulnerability I found in this UI automatically applies to all websites, it allows running...
In Microsoft Edge, URL Advisor UI is served as first-party content on every domain. So the XSS vulnerability I found in this UI automatically applies to all websites, it allows running...
Facebook Has Launched a Bug Bounty Program for Libra Blockchain
https://www.pcmag.com/news/370402/facebook-launches-bug-bounty-program-for-libra-blockchain
https://www.pcmag.com/news/370402/facebook-launches-bug-bounty-program-for-libra-blockchain
PCMAG
Facebook Launches Bug Bounty Program for Libra Blockchain
The Libra Association rolls out Libra Bug Bounty Program, offering up to $10,000 for uncovering critical blockchain security issues underlying the unreleased cryptocurrency.
CSRF leads to a stored self xss
https://hackerone.com/reports/323005
https://hackerone.com/reports/323005
HackerOne
Imgur disclosed on HackerOne: CSRF leads to a stored self xss
Followup from #311460
#Summary
Self xss and CSRF are both out of scope, but when paired it is possible to create an attack on a user.
#Description
A favorites folder with an xss payload for a...
#Summary
Self xss and CSRF are both out of scope, but when paired it is possible to create an attack on a user.
#Description
A favorites folder with an xss payload for a...
Google adds all Android apps with +100m installs to its bug bounty program
https://www.zdnet.com/article/google-adds-all-android-apps-with-100m-installs-to-its-bug-bounty-program/
https://www.zdnet.com/article/google-adds-all-android-apps-with-100m-installs-to-its-bug-bounty-program/
ZDNet
Google adds all Android apps with +100m installs to its bug bounty program
Google will pay security researchers for bugs they report in non-Google Android apps that have over 100 million installs.