Latest Posts

Bypassing locked profile restrictions on Facebook
Facebook allows certain users to set their Facebook profile to be "locked". This means other users are not able to view their full profile...

Launching internal & non-exported deeplinks on Facebook
The report was submitted as a collaboration between myself and Rahul Kankrale. The split was 70% Ash & 30% Rahul. It was possible...

ShazLocate!
Abusing CVE-2019-8791 & CVE-2019-8792
$('body > div.single-blog-area.section-padding > div > div > div:nth-child(1) > div > a').css('display','none'); I found a vulnerability...

Ability To Backdoor Facebook For Android
I found a security vulnerability in Facebook for Android which made it possible to backdoor the application. By abusing a development...

Downloading any file via Facebook for Android
.single-post-details blockquote{filter:none!important} The Facebook android app utilises deeplinks throughout the...

Breaking The Facebook For Android Application
Whilst working on the Facebook Bug Bounty Program in June 2018 we had identified an issue with...